OffPerimeter · Threat advisories
Campaign advisory
highPublished 2026-09-30 · 1 indicators

Exploitation of Citrix NetScaler Zero-Days to Deploy WHIPSHOT and SLAPSHOT Malware

Since at least early September 2026, suspected state-sponsored actors have been exploiting CVE-2026-88771 and CVE-2026-88772 in Citrix NetScaler ADC and Gateway appliances. The attackers gain unauthenticated remote code execution to install the WHIPSHOT PHP web shell and the SLAPSHOT Python tunneling tool. These tools allow the actors to maintain root-level persistence and bridge the gap between the compromised appliance and the victim's internal network for reconnaissance and credential theft.

ShareXLinkedInWhatsApp
First seen
2026-09-01
Last seen
2026-09-30
Threat actors
—
Malware
WHIPSHOT, SLAPSHOT
Sectors
Government, Financial Services, Education, Legal, Other
Countries
United States, United Kingdom, Germany, France

How it works

The attack begins with the exploitation of unauthenticated remote code execution vulnerabilities in Citrix NetScaler appliances. Once access is gained, attackers modify the web server configuration to map non-executable file extensions to PHP web shells and assert the setuid bit on /bin/sh to maintain root privileges. The WHIPSHOT web shell is then deployed to act as an HTTP proxy, which facilitates the deployment and command execution of the SLAPSHOT Python tunneling tool. This tunnel provides a path for the attackers to conduct internal reconnaissance, move laterally, and steal credentials from the internal network.

Techniques (MITRE ATT&CK)

Indicators

Indicators associated with this campaign in the sources we reviewed. Corroborate before blocking: an address or domain can be shared infrastructure.

IP addresses (1)
  • 149.104.78.141

What to do

References

ShareXLinkedInWhatsApp