Citrix NetScaler Pre-Authentication Vulnerability Exploited to Deploy Web Shells and Create Superuser Accounts
Threat actors leveraging a critical command injection flaw to gain persistent, unauthenticated access to NetScaler ADC and Gateway appliances

Key Takeaways
- Threat actors are actively exploiting a pre-authentication command injection vulnerability in Citrix NetScaler ADC and Gateway.
- The exploitation results in web shell deployment, superuser creation, and mapping of malicious files to CSS-like URLs for stealth.
- Actors are attempting to exfiltrate configuration data from compromised appliances.
Related Security News

Cisco Talos Identifies Antino Backdoor Leveraging Outlook and OneDrive in China-Nexus Espionage Campaign
Cisco Talos has uncovered a new cyberespionage campaign attributed to a China-nexus threat actor. The operation deploys a previously undocumented backdoor codenamed Antino, which specifically targets government and policy organizations across Asia. The backout leverages legitimate Microsoft services, including Outlook and OneDrive, for command and control communication, making detection more difficult. Victims have been identified in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar.



