# Citrix NetScaler Attacks Use Second‑Stage Payload to Add Hidden Superuser and PHP Web Shell

*Thursday, October 1, 2026 at 6:19 AM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-10-01T06:19:01.961Z (1h ago)
**Category**: cyber | **Region**: Global
**Importance**: 7/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/19320.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Attackers exploiting Citrix NetScaler flaws are deploying a second‑stage Perl script that creates a superuser account, hides a PHP web shell behind CSS‑style URLs, stages configuration data for upload, and then deletes itself.

Citrix NetScaler devices at the edge of corporate networks are being turned into persistent launch pads by attackers refining their tools after initial compromise.

New technical reporting describes how intruders exploiting NetScaler vulnerabilities are running a second‑stage Perl script on affected appliances. Once triggered, that script creates a superuser account and plants a PHP web shell disguised behind URLs that resemble requests for CSS or other benign resources.

Because NetScaler appliances handle heavy volumes of web traffic, a web shell hidden in apparently routine requests can be hard to pick out without targeted monitoring.

The Perl script does more than install a backdoor. It stages configuration data for upload, changing the device from a defensive gateway into a source of sensitive internal information. It also changes permissions on /bin/sh, making later command execution easier, and then erases itself once finished. That self‑deletion leaves fewer traces for incident responders trying to reconstruct what happened.

For organisations that depend on these devices for load balancing, application delivery and remote access, a covert superuser account and hidden shell on a NetScaler box provide attackers with a durable foothold right at the network edge.

Key indicators to track now are how quickly exposed appliances are patched or rebuilt, how many environments security teams find with the described artefacts already in place, and whether similar techniques appear on other brands of edge devices.
