Platypus Fleet Management Web UI
At a Glance
| Malware family | PHP web shells, a Perl web shell installer, Platypus agents, and a Python reverse shell |
| Threat actor | Four unnamed clusters; one uses a tool tied to China-nexus actors (suspected, not confirmed) |
| Targets | Citrix NetScaler appliances; eight eSentire customers across the post-disclosure clusters |
| Delivery vector | Exploitation of CVE-2026-88771, both before and after disclosure |
| Key capabilities | Root shell access, backdoor admin accounts, config theft, remote shell and file transfer |
| Sources | eSentire TRU; Mandiant and Google Threat Intelligence Group |
TL;DR
At least four groups exploited CVE-2026-88771 in Citrix NetScaler, starting before the flaw went public. They planted PHP web shells, gained root, and in one case stole NetScaler configs. Two clusters used a public proof-of-concept within 36 hours of its release.
Delivery
Citrix disclosed CVE-2026-88771 in its September 27, 2026 bulletin. Mandiant and GTIG, citing vendor disclosures, also noted attacks on it as a second NetScaler zero-day. eSentire now adds detail. It saw exploitation “as early as the beginning of September 2026.”
The pace sped up after disclosure. Cluster B struck about 24 hours later. Then watchTowr published a proof-of-concept on September 28. Clusters C and D used it within a day, and Cluster C even copied its fake crash message. eSentire says this shows “how quickly threat actors target internet-facing appliances.”
Infection Chain
Cluster A: The Zero-Day Web Shell
Cluster A hid a PHP web shell as a .deb package among real client files. The shell ran commands sent in an HTTP header. It also edited the Apache config to run PHP and set the SUID bit on the system shell for root access. Afterward, it scrubbed its install traces from the crontab.
eSentire says this shell is nearly identical to the “lightweight installer web shell” family GTIG described. GTIG tied that family to attacks on CVE-2026-88772, a separate NetScaler zero-day.
Cluster B: A Legitimate Fleet Tool
Cluster B hit three eSentire customers on September 28. Instead of malware, it installed Platypus, a legitimate open-source tool for managing fleets of Linux machines. The attackers used its default setup command with few changes. Platypus then gave them a shell, file management, and network tunneling.
Cluster C: Backdoor Accounts and Config Theft
Cluster C reached four customers on September 29. Its Perl script added a hidden superuser account to NetScaler. It also deleted other accounts, possibly to lock out rival attackers. Then it archived the NetScaler config folder and uploaded it.
The script planted a password-protected web shell disguised as a CSS file. As a result, requests to it look like normal page styling in Apache logs. eSentire also spotted “LLM-style comments,” hinting the attackers used AI to write the script.
Cluster D: Python Reverse Shell
Cluster D hit one customer the same day. It dropped a Python script that writes a reverse shell disguised as an SNMP service.
Command-and-Control and Data Theft
The NetScaler web shells were only part of the picture. Each cluster used its own channel. Platypus agents phone home over TLS to an attacker server. Cluster C’s web shell offers command execution and file upload and download through a browser. Cluster D’s reverse shell connects straight to a remote host.
Data theft is clearest in Cluster C. Its stolen NetScaler configs can hold credentials, certificates, and network details.
Attribution
eSentire does not name any group. Platypus has appeared in reporting on China-nexus actors, including Black Lotus Labs research on an IoT botnet. However, eSentire draws no firm link. So any China tie for Cluster B remains suspected, not confirmed.
Defense and Detection Guidance
The CVE-2026-88771 exploitation clusters share several traces. Defenders should:
- Apply Citrix’s fixed builds from the September 27 bulletin right away.
- Check the Apache config for PHP handlers on odd file types and new aliases.
- Look for the SUID or SGID bit set on the system shell.
- Review NetScaler configs for unknown superuser accounts.
- Search VPN and logon folders for disguised .deb, CSS, or journal files.
- Hunt for Platypus agents and unexpected processes posing as SNMP services.
If you find a web shell, assume configs and credentials are exposed. Rotate them after patching.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!