Attackers Actively Exploit Citrix NetScaler Vulnerabilities to Establish Web Shell Access

Cybersecurity researchers detected active exploitation of two previously unknown Citrix NetScaler remote code execution vulnerabilities affecting government, financial, and education sectors across North America and Europe. The attackers deployed custom web shells, tunneling malware, and gained root-level access to compromised appliances beginning in early September. Citrix released patches for both vulnerabilities following public disclosure, with researchers recommending defensive hunting for suspicious files that indicate successful exploitation attempts.
The discovered vulnerabilities represent two distinct weaknesses in Citrix's NetScaler appliances. One flaw permits unauthenticated attackers to execute code remotely on all ADC and Gateway models, while the second involves memory corruption tied to DTLS protocol functionality. Once inside compromised systems, adversaries systematically established persistent access through hidden web shells, disguised malicious files as legitimate system components, and modified web server configurations to mask their presence from standard detection methods.
Mandiant's investigation revealed attackers targeted organizations across multiple critical sectors during a coordinated campaign spanning at least three weeks before public disclosure. The attackers employed sophisticated post-exploitation techniques, including credential theft and lateral movement into internal networks, suggesting coordinated threat actors rather than opportunistic exploitation.
Organizations relying on Citrix NetScaler appliances for network access and security may face significant operational and security risks until systems are patched. Government agencies, financial institutions, and educational organizations potentially exposed could experience data breaches, service disruptions, or compromised infrastructure. The multi-week window between initial exploitation and public disclosure suggests many organizations may remain unaware of compromise, underscoring the challenges enterprises face detecting advanced persistent threats within critical network infrastructure components.