TENEX.ai Threat Intelligence Report: Citrix NetScaler Zero-Day Attackers Plants Footholds That Survive Patching
Analysis of newly discovered CVE-2026-88771 zero-day exploit traces attacker infrastructure to a command-and-control
Press Release Disclaimer: This is a press release distributed through the XPR Media network. It has not been independently verified by our newsroom.
![]()
Analysis of newly discovered CVE-2026-88771 zero-day exploit traces attacker infrastructure to a command-and-control cluster; TENEX releases more than 60 IOCs
SARASOTA, FL, UNITED STATES, October 5, 2026 /EINPresswire.com/ — TENEX, a fully-agentic, human-led security operations provider, released What TENEX.AI Observed Inside Active Exploitation of NetScaler Zero-Day on Oct. 1, documenting how attackers exploiting the Citrix NetScaler zero-day are installing a superuser account, hidden web shell and command-and-control agent that remain on the appliance even after it is patched.
Based on TENEX Threat Intelligence analysis of exploitation attempts against a NetScaler Gateway and payloads recovered from the attacker’s staging servers, the report maps the operator’s infrastructure to a four-node cluster sharing a single TLS certificate. Citrix released fixed builds on Sept. 27, CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day, and a public proof-of-concept on Sept. 28 was followed by mass scanning within a day.
Bashar Abouseido, President, TENEX: “Threat actors are using AI to compress the time between identifying a vulnerability, exploiting it, and at times to reverse engineer a patch. The speed of this one fits that pattern. The adversary isn’t waiting for anyone to catch up, so neither can we.”
Report Highlights
– Four staging servers used in roughly a day: The exploitation attempts rotated through four staging servers, each serving a different payload over a different port and download method. One path led to the Platypus agent, one to a Perl post-exploitation script, one to a Python reverse shell, and one to a direct binary download.
– One certificate exposed the cluster: All four command-and-control nodes present the same self-signed certificate, and a single pivot on its fingerprint turned one suspicious address into the full cluster. The certificate’s public-key hash and issuing CA give defenders pivots that survive a reissue.
– Footholds survived the patch: The Perl stage writes a superuser account named sec_monitor into the saved configuration, sets the SUID bit on /bin/sh, exfiltrates the configuration directory, and aliases a PHP web shell behind a stylesheet URL on the Citrix logon page. The Python stage replaces the appliance’s customsnmpd daemon with a reverse shell that NetScaler restarts itself.
– An agent built to outlast blocklists: The Platypus binary carries no C2 address. A bootstrap hands it the server and a one-time install token and installs it under appliance-style paths renamed as a NetScaler Perl script. Every build carries the same operator signing key, which outlasts any rebuild.
– Two waves over one flaw: A disciplined operator rebuilding its agent as the patch shipped, and a separate wave of commodity tooling (Global Socket Toolkit, netcat) after the public proof-of-concept. TENEX does not attribute the activity to a named actor.
Recommended Actions
The report recommends that any organization running NetScaler ADC or Gateway:
– Upgrade now: Move to 14.1-73.37, 13.1-64.23, or the FIPS and NDcPP equivalents, after confirming the identity provider signs SAML assertions.
– Check before clearing: On any appliance exposed before the upgrade, look for the sec_monitor account, a setuid /bin/sh, unexpected files under LogonPoint/, httpd.conf alias changes, a modified customsnmpd, and a client certificate under /var/core/.ns-cache/.
– Rotate after upgrading: Replace every credential, key, and certificate the appliance could reach, then revoke active sessions.
– Monitor the segment: Watch the appliance’s local network for the agent’s _platypus-mesh._tcp mDNS announcement.
To read the full report and download the indicator set, visit the TENEX.ai blog post “What TENEX Observed Inside Active Exploitation of NetScaler Zero-Day” at https://tenex.ai/blog/what-tenex-observed-inside-active-exploitation-of-netscaler-zero-day/
TENEX.AI PR
TENEX.AI
+1 650-605-7865
email us here
Visit us on social media:
LinkedIn
Facebook
X
Legal Disclaimer:
EIN Presswire provides this news content “as is” without warranty of any kind. We do not accept any responsibility or liability
for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this
article. If you have any complaints or copyright issues related to this article, kindly contact the author above.
![]()
Media gallery

