Arctic Wolf details post-exploit NetScaler attacks
Wed, 30th Sep 2026 (Today)
Arctic Wolf Labs has published threat intelligence on attacks exploiting Citrix NetScaler vulnerabilities, based on activity observed on compromised devices.
The research examines what intruders did after gaining access to vulnerable NetScaler appliances, shifting the focus from the software flaws themselves to post-exploitation behaviour on affected systems.
Researchers observed command injection and remote code execution activity targeting exposed devices. They also documented the retrieval and execution of malicious Python, Perl and shell scripts, along with attempts to establish reverse-shell access and run remote commands.
The report also identifies persistence measures designed to remain in place after remediation begins. That suggests some organisations may need to do more than install updates if attackers had already reached the systems before patches were applied.
Post-exploitation activity
One of the more detailed findings concerns a Perl-based tool used by attackers. The tool attempts to establish persistence, create a TCP listener, gather host information and maintain access to compromised machines.
That sequence points to a shift from initial exploitation to longer-term control of a target environment. Security teams investigating vulnerable NetScaler deployments may therefore need to determine whether appliances were used as an entry point for follow-on activity inside broader networks.
The threat intelligence comes amid broader scrutiny of NetScaler security following warnings from the Australian Cyber Security Centre and confirmation from Citrix that multiple vulnerabilities were being actively exploited. Arctic Wolf's findings add technical detail on what attackers did after securing access.
Indicators for defenders
Alongside its analysis, Arctic Wolf compiled indicators of compromise that defenders can use in their own investigations. Incident response and security operations teams typically use such indicators to check whether known malicious files, processes, network connections or system changes are present in their environments.
The reported use of Python, Perl and shell scripts is likely to draw attention because scripting tools can be deployed quickly on internet-facing appliances and may leave traces for investigators to review. Reverse-shell attempts are also significant because they can give attackers a way to issue commands remotely after the initial breach.
Persistence remains a central concern in incidents involving perimeter devices. If a mechanism survives patching or partial clean-up, organisations can face continued unauthorised access even after they believe the original vulnerability has been addressed.
For that reason, the findings suggest incident review should accompany patching efforts for any organisation that exposed vulnerable NetScaler systems to the internet. In practice, that may involve reviewing logs, inspecting appliances for unauthorised scripts or listeners, and checking for signs of outbound connections associated with reverse shells.
The report underlines a familiar issue in vulnerability response: fixing the software flaw does not by itself confirm that no compromise occurred before the update was applied. Where exploitation is active in the wild, defenders often need to treat patching and compromise assessment as separate tasks.
Arctic Wolf said its researchers had documented detailed indicators of compromise for immediate investigation by security teams.