grep -rl "NetScaler" ./posts

#NetScaler

3 matches

The Biography of a Bulletproof Box: Nine Months with the NetScaler Copycat's Server

Third piece in the pitboss series: the second wave's collector at 213.209.159.55 is still live, still serving per-target droppers, and its code evolved from gen-3 to v19-plus while I watched. Full teardown of the forced HA-failover logic and the three-channel C2 (one-shot relay, 15-second pull tasking with output return, HTTP front), why the exfil side is write-only and what that means for victims, the nine-month attack history of the address (January port scans, February .env probes, March .git probes via Go-http-client, Ligolo-ng tunnels in October), a correction to my own domain-aging claim, and the detection set that matters now.

2026-10-04 · 10 min

Twenty in Eighteen Hours: Tracking the NetScaler Second Wave Through Its Own Constants

A follow-up investigation to the pitboss teardown: pivoting the public malware corpus on the passwords, tokens, and placeholder strings extracted from the campaign samples turns two copycat bundles into a twenty-deployment operation with three code generations, surfaces chisel on the exfil host, doubles the Platypus enrollment count, and recovers a victim's implant config that phoned a lab address that does not exist. With the pivot methodology, its traps (the MD5 test vector that fakes attribution), and expanded IOCs.

2026-10-03 · 11 min

Pitboss Never Sleeps: Reverse Engineering the NetScaler Log-to-Root Chain (CVE-2026-88771 / CVE-2026-88772)

Full teardown of the September 2026 NetScaler ADC/Gateway zero-day campaign: the ns_monuploadd_err.pl log-poisoning root cause analyzed line by line from firmware, the watchTowr DTLS heap-overflow PoC dissected down to its setcontext/ROP chain, and the complete payload landscape grounded in first-hand analysis of 18 in-the-wild campaign samples: the dual-mode webshell installers, update_c08937.pl with its plaintext passwords, the nsmon.pl cron bind shell no vendor named, Platypus enrollment certificates that date the C2 infrastructure to September 2, and a post-disclosure WHIPSHOT/SLAPSHOT copycat kit. With detection and eradication guidance.

2026-10-03 · 44 min

← back to listing