Threat actors are exploiting a critical pre-authentication command injection flaw in Citrix NetScaler ADC and NetScaler Gateway to drop web shells, create privileged accounts on compromised appliances, and attempt to steal configuration data, according to an account published by The Hacker News of research from LevelBlue's Threat Hunt Operations & Research (THOR) team.

The research, as reported on 1 October 2026, draws on investigations across multiple customer environments. The campaign follows a pattern now familiar in edge-appliance exploitation: an unauthenticated entry point on a network-facing device, followed by rapid post-exploitation to entrench access and harvest credentials.

A note on sourcing: this article reflects The Hacker News' reporting of LevelBlue's findings. The write-up, as reported, does not disclose a specific CVE identifier or a definitive list of affected firmware versions, and this article will not speculate on either. Organizations seeking authoritative scope should consult Citrix's own security advisory directly rather than relying on secondhand version lists.

What the attackers are doing

According to the reported LevelBlue findings, once the initial command injection is achieved, the operators attempt to create privileged — in effect, superuser — accounts for themselves on the appliance, removing any dependence on the original exploit vector. That step alone makes persistence far harder to undo: an organization that patches the underlying vulnerability may still be running attacker-controlled administrator credentials.

The web shells themselves are notable for their camouflage. Rather than using conspicuous filenames, the payloads are hosted at URLs designed to blend in with legitimate static assets, resembling Cascading Style Sheets (CSS) resources. The intent is straightforward — keep the implants out of routine log reviews and endpoint alerts. Detection logic that keys on suspicious filenames or shell extensions will miss this activity entirely.

Compounding the risk, the attackers also attempt to exfiltrate NetScaler configuration data. That typically includes private keys, certificates, session-signing keys, and authentication state. Any of those materials can be useful to an intruder long after the original vulnerable appliance has been patched, because they may still be valid for other systems or for impersonating the organization's authenticated users.

Why it matters

NetScaler ADC and Gateway remain widely deployed enterprise remote-access components, which means the blast radius of a pre-authentication command injection on these devices is substantial — they sit at the boundary between the internet and internal services. The campaign also fits a longer lineage of NetScaler exploitation: the platform has been repeatedly targeted over the years through pre-authentication vulnerabilities, including well-documented campaigns in 2019 and 2023. In that context, "we patched the last flaw" is not the same as "we are current" — these appliances need continuous monitoring, not just occasional patching.


Analysis: what HKLUG Team readers should do

The following is the HKLUG Team's own synthesis, informed by — but not attributed to — LevelBlue's findings.

For Hong Kong IT and security teams operating internet-facing NetScaler or similar edge appliances, the practical relevance is broad: the technique described does not depend on region, and the remediation obligations it implies are universal. To be clear, we are not asserting that any local incident has occurred, nor drawing any implication about local regulatory posture — the point is simply that any organization running these appliances should treat the guidance below as applicable.

Informed by the reported LevelBlue findings, we would suggest the following hunting steps:

  • Cross-reference web requests on NetScaler appliances against known legitimate static assets. CSS-like URLs should be reconciled against a baseline of real files before being dismissed.
  • Review account and configuration change logs on the device. Unauthorized administrative accounts, newly added certificates, or modified virtual servers are high-signal indicators.
  • Compare the running process list on the appliance against the expected NetScaler service set — unexpected processes are a strong sign of implant activity.
  • Check for unauthorized certificates or virtual servers, since certificate and key harvesting is a documented objective of this campaign.
  • Treat configuration data as potentially compromised if the appliance was vulnerable during the exploitation window, even after the access point itself is closed.

Patch management, file-integrity monitoring, egress monitoring, and privileged-account auditing on edge devices are now baseline expectations, not optional extras. Perimeter appliances are themselves the attack surface, and they deserve endpoint-grade scrutiny — the absence of an obvious shell file in a log does not mean the device is clean.


據 The Hacker News 報道的 LevelBlue Threat Hunt Operations & Research(THOR)團隊研究顯示,威脅行為者正利用 Citrix NetScaler ADC 及 NetScaler Gateway 的一個 pre-authentication command injection 嚴重漏洞植入 web shell、在被入侵的裝置上建立權限帳戶,並嘗試竊取設定資料。

上述研究由 The Hacker News 於 2026 年 10 月 1 日報道,涵蓋多個客戶環境的調查。此次攻擊行動的模式,在周界裝置(perimeter appliance)漏洞利用中已屬常見:先以網絡面向設備上的無需驗證入口為突破點,隨即展開快速的 post-exploitation,鞏固存取權限並收集憑證。

關於資料來源,這裡有一點說明:本文反映的是 The Hacker News 對 LevelBlue 發現的報道。據現有報道,有關報告並未披露具體的 CVE 編號,亦未提供明確的受影響韌體版本清單,本文不會對此加以猜測。如機構需要權威的影響範圍資料,應直接查閱 Citrix 自己的安全公告,而非依賴二手版本清單。

攻擊者在做甚麼

根據 The Hacker News 報道的 LevelBlue 發現,一旦 initial command injection 得手,攻擊者便會嘗試在裝置上自行建立權限帳戶——實際上即是 superuser——從而擺脫對原始 exploit vector 的任何依賴。單是這一步驟,已令持久化後門難以根除:即使機構修補了底層漏洞,攻擊者所控制的管理員憑證可能仍在運作之中。

web shell 本身最大的特點在於其偽裝手法。這些惡意載荷並非使用顯眼的檔案名稱,而是安裝於精心設計、看似與合法 static assets 融為一體的網址上,外觀酷似 Cascading Style Sheets(CSS)資源。意圖十分明顯——令植入程式躲過日常日誌審查及 endpoint 告警。任何以可疑檔案名稱或 shell 擴展名為偵測條件的檢測邏輯,都會完全錯過這次活動。

風險更為加劇的是,攻擊者還會嘗試外洩(exfiltrate)NetScaler 的設定資料。這通常包括私鑰、證書、session signing key 及身份驗證狀態(authentication state)。即使原始的受漏洞影響裝置其後已修補,入侵者仍可長時間利用上述資料——因為它們可能對其他系統仍然有效,或可用於冒充該機構已驗證的用戶。

為何重要

NetScaler ADC 及 Gateway 依然是廣泛部署的企業遠端存取元件,這意味著這些設備上一旦出現 pre-authentication command injection,其爆炸半徑(blast radius)相當巨大——它們正處於互聯網與內部服務之間的邊界位置。這次攻擊行動亦屬於更長的 NetScaler 漏洞利用脈絡:多年來該平台屢次因 pre-authentication 漏洞而成為目標,其中包括 2019 年及 2023 年有詳細記錄的攻擊行動。在這個背景下,「我們已修補上一個漏洞」與「我們的系統處於最新狀態」是兩回事——這些裝置需要的是持續監控,而非偶爾修補一次。


分析:HKLUG 讀者應採取的行動

以下為 HKLUG 團隊的自行整理,參考 LevelBlue 的發現,但並非出自 LevelBlue。

對於在香港運行互聯網面向 NetScaler 或類似周界裝置的 IT 及安全團隊而言,本文所述技術具備廣泛的實際相關性:文中所述手法不依賴於地區,其衍生的補救責任亦是普遍適用的。在此必須澄清,我們並非斷言本港已發生任何事故,亦未對本地監管立場作出任何暗示——重點只在於,任何運行上述裝置的機構,都應將以下指引視為適用。

綜合 The Hacker News 報道的 LevelBlue 發現,我們為安全團隊建議以下 threat hunting 步驟:

  • 將 NetScaler 裝置上的 web 請求與已知的合法 static assets 進行交叉比對。類似 CSS 的網址應先與真實檔案的基線(baseline)核對,方可加以排除。
  • 檢視裝置上的帳戶及設定變更日誌。未經授權的管理員帳戶、新近加入的證書,或被修改的 virtual server,均屬高度相關的指標。
  • 將裝置上運行的 process list 與預期的 NetScaler 服務組合進行比對——意外出現的 process 是植入程式(implant)活動的強烈跡象。
  • 檢查是否存在未經授權的證書或 virtual server,因為收集證書及密鑰正是這次攻擊行動有明確記錄的目標之一。
  • 若裝置在漏洞利用期間曾受影響,即使入侵入口本身已被封閉,仍應將設定資料視為可能已被污染。

補丁管理(patch management)、檔案完整性監控、出站流量監控(egress monitoring),以及周界裝置上的特權帳戶審計,如今已是基本要求,而非可有可無的附加項目。周界裝置本身就是攻擊面(attack surface),應獲得以 endpoint 級別的嚴格審視——日誌中沒有明顯的 shell 檔案,並不等於裝置乾淨。

新聞來源 / Original News Source