Published: · Region: Global · Category: cyber

Citrix NetScaler Hackers Create Stealth Superuser and Web Shells on Edge Appliances

Attackers exploiting Citrix NetScaler are deploying a second‑stage payload that adds a superuser account, hides a PHP web shell behind CSS‑style URLs, and quietly alters core system settings. For organisations that rely on NetScaler to front key applications, the appliances themselves have become high‑value footholds.

Citrix NetScaler appliances that many organisations use to manage web traffic are being turned into persistent beachheads for attackers. New technical reporting shows that intruders targeting NetScaler are installing a second‑stage payload that does much more than trigger a one‑off exploit, creating a stealth superuser account and hiding a web shell behind URLs that resemble harmless style‑sheet calls.

Once attackers gain initial access to a vulnerable NetScaler, they run a Perl script that performs several post‑exploitation steps. The script prepares configuration data for upload, alters file permissions by changing how /bin/sh can be used, and then deletes itself after execution. Alongside this, the operators deploy a PHP web shell with access paths masked as CSS‑like URLs so that malicious requests blend into normal web traffic.

The addition of a superuser account on these devices is especially serious. NetScaler appliances sit at the edge of many corporate networks, handling tasks such as authentication, load balancing and access to internal applications. A hidden privileged account there gives attackers a durable position from which they can inspect sensitive traffic, collect credentials, alter sessions or move deeper into internal systems.

For defenders, this turns a NetScaler incident into more than a patching exercise. When a second‑stage payload like this is present, the appliance is functioning as an attacker‑controlled node with broad visibility. Recovery can require reinstalling firmware, reviewing configuration files in detail and, in some cases, rotating passwords and keys that may have passed through the device.

The use of self‑deleting scripts and web shells disguised as benign resources shows that the intruders are aiming for long‑term access rather than quick theft. They expect to remain in place, quietly exfiltrating data or waiting for commands, rather than triggering obvious disruptions that would expose their presence.

This campaign fits a broader pattern of attackers going after network edge equipment such as gateways, firewalls and load balancers. These systems often sit outside the view of traditional monitoring tools, log less information by default and are rarely treated with the same scrutiny as servers or user endpoints. Once compromised, they offer attackers privileged placement and relative invisibility.

The lesson for organisations is direct: edge appliances need to be treated as critical assets. That includes maintaining an inventory of exposed devices, applying security fixes quickly, enabling logging where possible and watching closely for signs of tampering such as unexpected administrative accounts or unfamiliar outbound connections.

In the short term, security teams will be looking for updated guidance from Citrix, new detection rules from security vendors that can spot the CSS‑masked web shells, and forensic analyses that clarify which threat actors are using this second stage. If evidence emerges that attackers are automating this payload at scale, the issue will move from a series of targeted compromises to a widespread infrastructure problem across enterprises that depend on NetScaler.

Sources