Threat Brief — 2026-10-01 — NetScaler Post-Exploitation Evolves
Executive summary: New technical details have emerged on how threat actors are operating after exploiting the critical pre-authentication command injection flaw in Citrix NetScaler ADC and Gateway. Post-exploitation payloads now create superuser-level accounts and map web shells to CSS-like URL paths to evade detection. This is the latest development in an ongoing exploitation campaign that CISA added to its Known Exploited Vulnerabilities catalog in mid-August.
Top items
- Citrix NetScaler post-exploitation refined with superuser creation and CSS-disguised web shells. Threat actors exploiting the critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway (CVE-2025-62593KEV) have been observed deploying post-exploitation payloads that create superuser accounts and register web shells at CSS-like URL paths to blend into legitimate web traffic. Actors are also attempting theft of configuration data. This extends the ongoing NetScaler exploitation story first reported 2026-08-17 via CISA's KEV catalog addition; the new development is the disclosure of specific superuser-creation and CSS-camouflage techniques by LevelBlue's Threat Hunt operation. This vulnerability is in CISA's Known Exploited Vulnerabilities catalog. (src: The Hacker News)
Themes
Defensive evasion through mimicry. The CSS-like URL mapping for web shells is part of a broader pattern of threat actors camouflaging malicious activity inside legitimate-looking traffic and file paths — making log analysis and URL filtering more critical than signature-based detection alone.
