GreyNoise observes adversary activity through our Global Observation Grid (GOG), a network of sensors that draws attacker scanning and exploitation onto infrastructure we control. This lets us study adversary infrastructure, tooling, and tradecraft directly, without waiting for a victim investigation. GreyNoise also expands the GOG through Project Swarm, which enables the broader security community to join the effort. The activity discussed in this blog was derived from a Swarm participant sensor. 

On 24 September 2026, a malicious cyber actor (MCA) used 149.104.78.141 to attempt zero-day exploitation against a Citrix NetScaler Gateway. At the time, there were no CVE-specific detections for the attack due to it occurring pre-disclosure. However, GreyNoise still detected and labeled the activity as fundamentally malicious within seconds due to behavioral detections. GreyNoise will not publish full details of the exploitation chain at this time. Patches are available and post-exploitation details are included below.

‍

Exploitation before disclosure

TimelineTLP:CLEAR
Citrix NetScaler CVE-2026-88771
GreyNoise saw CVE-2026-88771 exploitation attempts on Sep 24, more than three days before public disclosure. The CVE-specific tag, deployed Sep 27, retro-tagged that activity.
7 dated events on 3 daysRetro-tagged as CVE-2026-88771 exploitationSelect a date to read it.
13 days
Sep 10, 2026 · 07:14:57 UTC
NetScaler reserves CVE ID.
Open on the full timeline →
Sep 24, 2026 · 07:32:08 UTC
Initial reconnaissance begins.
Intention is not known. Every Sep 24 entry here comes from this one IP address.
Sep 24, 2026 · 07:32:15 UTC
GreyNoise labeled the IP address suspicious due to methodology-based detection.
Sep 24, 2026 · 07:32:19 UTC
GreyNoise labeled the IP address malicious.
Sep 24, 2026 · 07:32:19 UTCRetro-tagged as CVE-2026-88771 exploitation
GreyNoise observed CVE-2026-88771 exploitation attempts from this IP address.
(Citrix NetScaler CVE-2026-88771 Login Command Injection RCE Attempt) Retro-tagged after the tag's Sep 27 deployment: 3 sessions, 07:32:19 to 07:32:20 UTC.
Open on the full timeline →
Sep 27, 2026 · 15:51:00 UTC
Public disclosure of CVE-2026-88771.
Sep 27, 2026 · 20:28:39 UTC
GreyNoise deployed the CVE-specific tag.
(Citrix NetScaler CVE-2026-88771 Login Command Injection RCE Attempt) Its retro hunt of stored sessions tagged only the Sep 24 activity.
Open on the full timeline →
Source: CVE record; GreyNoise.
Times are UTC.
GreyNoise

‍

Post-Exploitation

Though the adversary was unsuccessful in gaining a foothold on the targeted Swarm sensor, their post-exploitation playbook was revealed.

The MCA attempted to set both the Set User ID (setuid) and Set Group ID (setgid) bits on /bin/sh to obtain a root shell and install a password-protected webshell that accepts communication by the cookie value sent by the adversary. This may be to avoid persisting their commands in web logs. The MCA then attempted to configure the web server to treat their installed dot file (.ctxs.receiver - hidden by default) as a PHP file despite not having a .php extension. The MCA tried to create an alias which would route requests for a non-existent cascading style sheet (CSS) (receiver.min.css) to .ctxs.receiver; the MCA also attempted to create an additional AliasMatch setting which would provide similar functionality but allow for a more flexible pattern match so that variable characters added to the receiver.min.[0-9a-f].css file path would still route to the webshell. Lastly, the adversary attempted to kill the httpd process to restart the server.

‍

Indicators of Compromise

There are other indicators being shared in the community at a higher Traffic Light Protocol (TLP) level than we can put in this blog; none of the indicator sets should be considered exhaustive. Due to the nature of the vulnerability, adversaries have a wide range of options to poison server logs with variable malicious payloads as part of the exploitation sequence.

Indicator Description
149.104.78.141 Exploitation
/var/netscaler/logon/LogonPoint/custom/.ctxs.receiver Webshell
Path (Disk)
receiver.min.css Alias
(Webshell)
receiver\\.min\\.[0-9a-f]+\\.css AliasMatch
(Webshell)
6f5a2a452a7901323abd21879c6cecccb47c06aeeaccb1b467212f3b11e4b1e7 Webshell
SHA-256
This article is a summary of the full, in-depth version on the GreyNoise Labs blog.
Read the full report
GreyNoise Labs logo
Link to GreyNoise Twitter account
Link to GreyNoise Twitter account