Hackers Camouflage PHP Web Shells as Citrix CSS Files

A seemingly innocuous cascading style sheet (CSS) address upon a standard Citrix login page has metamorphosed into an elaborate camouflage for covert, persistent remote access. The elite LevelBlue cybersecurity team unearthed a sophisticated post-exploitation toolkit actively deployed in devastating attacks targeting NetScaler ADC and Gateway appliances. This toolkit is meticulously engineered to fabricate highly privileged administrative accounts, exfiltrate sensitive configuration parameters, and implant insidious PHP web shells, seamlessly masquerading behind URLs that mimic authentic CSS resources. Investigators confirmed the presence of this malicious toolkit across multiple compromised client environments simultaneously.
Exploiting CVE-2026-88771 for Initial Access
The primary vector for these incursions remains CVE-2026-88771, a critical vulnerability commanding an alarming 9.5 rating on the CVSS 4.0 scale. This profound input validation failure enables absolute, unauthenticated remote command execution. Disturbingly, it afflicts default NetScaler configurations entirely devoid of tangential, supplementary features or esoteric, non-standard settings. By late September, cybersecurity analysts confirmed that threat actors had aggressively exploited dual zero-day vulnerabilities within this product lineage well before formal public disclosure and the subsequent issuance of mitigating patches.
Following a successful primary exploitation, the adversaries invariably download and execute a pernicious Perl script designated update_c08937.pl. This script maliciously alters the core ns.conf file, instantiating a clandestine local account christened sec_monitor while elevating its privileges to the “superuser” role. Subsequently, it archives the critical /flash/nsconfig directory to facilitate seamless exfiltration. Once this archive successfully transmits to an external command-and-control server, the script autonomously annihilates both the temporary archive and itself, striving to minimize detectable forensic artifacts upon the physical disk.
The Deceptive Web Shell Architecture
The most sophisticated obfuscation occurs deep within the web server architecture. The installation script strategically deposits the PHP web shell payload directly into a file deceptively named .local_journal. It then maliciously modifies httpd.conf to enable PHP processing and intricately binds this clandestine shell to URLs deliberately structured to mimic benign NetScaler style sheets. Among the myriad variations identified, LevelBlue isolated LogonUISimple.html.style.min.css alongside numerous filenames incorporating dynamically mutating hexadecimal fragments. This robust web shell grants the attackers the terrifying capacity to execute arbitrary system commands and effortlessly transfer files in both directions.
However, the adversaries do not restrict their persistence mechanisms exclusively to the web interface. The payload aggressively modifies the permissions of /bin/sh to 6555, guaranteeing a permanent, accessible pathway to a highly privileged command shell. Concurrently, an autonomous Python script, main.py, initiates a resilient reverse TCP connection utilizing port 443 and ruthlessly terminates any processes affiliated with customsnmpd. In tangential operational episodes, the attackers initially executed a standard whoami command before deploying utilities such as curl or wget to retrieve and deploy supplementary malicious components.
Forensic Evasion and Tangential Threats
The deliberate, automated deletion of specific files severely complicates the forensic analysis of an already compromised appliance. LevelBlue urgently recommends that administrators relentlessly hunt for the sec_monitor account, unauthorized modifications to ns.conf and httpd.conf, anomalous permissions assigned to /bin/sh, the presence of the .local_journal file, and any suspicious network connections communicating with known attack infrastructure. Crucially, the total absence of the temporary archive or the initial Perl script does not definitively prove that the malicious post-exploitation phase remained dormant.
Simultaneously, threat actors are aggressively exploiting a secondary critical flaw, CVE-2026-88772, which also carries a formidable 9.5 CVSS 4.0 rating. Launching an attack exploiting this specific vulnerability requires the Datagram Transport Layer Security (DTLS) protocol to be active, a state currently enabled by default on the VPN vServer. The successful exploitation of CVE-2026-88772 has directly facilitated the devastating deployment of the WHIPSHOT and SLAPSHOT malware strains, effectively mutating the perimeter gateway into a fully compromised conduit plunging directly into the internal corporate network. Citrix officially acknowledges the active, real-world exploitation of both vulnerabilities.
Remediation Mandates
Citrix is urgently imploring organizations to upgrade their infrastructure immediately to at least NetScaler version 14.1-73.37 or 13.1-64.23. Furthermore, the corporation has provided distinct, specialized builds for environments mandating FIPS and NDcPP compliance. While the comprehensive update definitively patches the vulnerabilities, it inherently cannot eradicate persistence mechanisms already established by the attackers. For any appliances potentially compromised prior to the patch application, administrators face the arduous necessity of conducting exhaustive, manual sweeps for lurking web shells and definitively rotating all associated authentication credentials.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.