Citrix NetScaler Exploitation: Superuser Creation and Web Shell Mapping via CSS-Like URLs
Threat actors are exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler to create superuser accounts and deploy web shells mapped to CSS-like URLs. The attack involves post-exploitation payloads like Python and Perl scripts for reverse shells, configuration data exfiltration, and persistent access.
Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data.
LevelBlue's Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler
*** END OF TRANSMISSION ***