Citrix NetScaler devices have become active targets for post-exploitation abuse. Threat actors exploiting a pre-authentication command injection vulnerability in NetScaler ADC and Gateway instances now deploy web shells disguised as CSS files and create superuser accounts to maintain persistence, according to LevelBlue's Threat Hunt Operations and Research team.
The vulnerability allows unauthenticated attackers to execute arbitrary commands on vulnerable NetScaler instances before authentication occurs. Once inside, threat actors follow a clear operational pattern. They create hidden administrative accounts with superuser privileges, ensuring they retain access even after the initial vulnerability patch closes. They then install web shells mapped to benign-looking URLs that mimic CSS stylesheets, blending malicious traffic with legitimate web requests. This obfuscation technique helps evade detection tools scanning for suspicious file extensions or suspicious web activity.
LevelBlue's THOR team observed this exploitation pattern across multiple customer environments, indicating active, widespread compromise. The attackers also attempt to exfiltrate NetScaler configuration data, which typically contains sensitive information including authentication credentials, policy settings, and internal network topology details. Configuration theft compounds the breach severity beyond initial shell access.
Citrix NetScaler ADC and Gateway products function as crucial perimeter security appliances. Organizations deploy them to manage traffic, enforce access policies, and protect internal networks from direct exposure. A compromised NetScaler instance becomes an inside adversary, positioning attackers to monitor, intercept, or redirect all traffic flowing through the device. The pre-authentication nature of the vulnerability makes exploitation trivial. Attackers need no valid credentials, no social engineering, no phishing. Internet-facing NetScaler devices become immediately vulnerable upon deployment if patches lag.
The CVE identifier for this vulnerability confirms Citrix recognized the flaw's severity. Organizations operating NetScaler ADC or Gateway instances must assume compromise if they have not applied patches. The post-exploitation artifacts described by LevelBlue provide detection signatures. Organizations should hunt for newly created administrative accounts, particularly those with generic or system-like names. They should search proxy logs for requests to CSS file URLs returning executable content or unusual response sizes. Configuration backup files accessed by unauthorized processes warrant investigation.
Rapid patching remains non-negotiable. NetScaler devices typically manage critical path traffic, making updates operationally risky. Many organizations delay patches due to uptime concerns. The active exploitation observed by LevelBlue eliminates the luxury of delay. Threat actors actively hunt for unpatched instances. Delaying patches extends the window for compromise.
Organizations should also implement network segmentation isolating NetScaler management interfaces from untrusted networks. Management access should require multi-factor authentication and allow connections only from restricted IP ranges. Log aggregation and SIEM ingestion of NetScaler audit logs enables faster detection of administrative account creation or configuration changes.
The web shell disguise as CSS files represents mature post-exploitation tradecraft. Threat actors employ this technique because it works. Security teams often whitelist CSS requests as low-risk. Mapping shells to CSS-like URLs exploits this blind spot. Organizations should enforce strict validation of CSS file content types and response headers, blocking any CSS request returning executable code or unexpected content.
