logo

Citrix Netscaler backdoors — Part One — May 2025 activity against governments

ID: a2f643fa-8d34-5c1c-bdd4-2d1069ab3013

STIX ID: report--a2f643fa-8d34-5c1c-bdd4-2d1069ab3013

Feed Name: DoublePulsar

Threat Score
80/100

Date Published: 2025-08-31

Date Updated: 2026-04-19

Author: Kevin Beaumont

...
...

This report documents an active campaign targeting Citrix NetScaler appliances via a vulnerability in getAuthenticationRequirements.do. Attackers POST specially constructed payloads that use base85/zlib/pickle unpacking in Python to drop XOR-decrypted PHP webshells that accept AES-encrypted commands; they also create a SUID shell for privilege escalation, time-stomp legitimate files (e.g., jquery.min.js), and restart Apache to maintain access. Detection guidance includes monitoring POST requests to getAuthenticationRequirements.do, searching for web-accessible PHP shells in LogonPoint/theme paths, checking for unexpected /var/python/bin/python3 executions and SUID binaries (e.g., /var/tmp/sh), and investigating anomalous Last-Modified headers on static assets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.