Exploitation of Citrix NetScaler Zero-Days to Deploy WHIPSHOT and SLAPSHOT Malware
Since at least early September 2026, suspected state-sponsored actors have been exploiting CVE-2026-88771 and CVE-2026-88772 in Citrix NetScaler ADC and Gateway appliances. The attackers gain unauthenticated remote code execution to install the WHIPSHOT PHP web shell and the SLAPSHOT Python tunneling tool. These tools allow the actors to maintain root-level persistence and bridge the gap between the compromised appliance and the victim's internal network for reconnaissance and credential theft.
- First seen
- 2026-09-01
- Last seen
- 2026-09-30
- Threat actors
- —
- Malware
- WHIPSHOT, SLAPSHOT
- Sectors
- Government, Financial Services, Education, Legal, Other
- Countries
- United States, United Kingdom, Germany, France
How it works
The attack begins with the exploitation of unauthenticated remote code execution vulnerabilities in Citrix NetScaler appliances. Once access is gained, attackers modify the web server configuration to map non-executable file extensions to PHP web shells and assert the setuid bit on /bin/sh to maintain root privileges. The WHIPSHOT web shell is then deployed to act as an HTTP proxy, which facilitates the deployment and command execution of the SLAPSHOT Python tunneling tool. This tunnel provides a path for the attackers to conduct internal reconnaissance, move laterally, and steal credentials from the internal network.
Techniques (MITRE ATT&CK)
- T1190 · initial_accessExploit Public-Facing ApplicationAttackers exploit critical flaws in NetScaler for unauthenticated remote code execution.
- T1505.003 · persistenceWeb ShellThe threat actor changes the appliance web server configuration to plant and run web shells with root privileges.
- T1021 · lateral_movementRemote ServicesThe deployed malware enables lateral movement within the victim's internal network.
- T1003 · credential_accessOS Credential DumpingThe tools are used to facilitate credential theft from the targeted environment.
- T1543.003 · persistenceWindows ServiceThe threat actor leverages web shells to assert the setuid bit on the /bin/sh executable to establish persistent root-level execution.
- T1564.001 · defense_evasionHidden Files and DirectoriesAttackers modify the web server configuration so requests for files like CSS appear to be legitimate while opening a hidden PHP web shell.
- T1090.002 · command_and_controlExternal ProxyThe WHIPSHOT malware acts as an HTTP proxy for SLAPSHOT, extracting data from request headers to forward to the tunneling malware.
Indicators
Indicators associated with this campaign in the sources we reviewed. Corroborate before blocking: an address or domain can be shared infrastructure.
- 149.104.78.141
What to do
- Apply Citrix security updates for CVE-2026-88771 and CVE-2026-88772 immediately.
- Disconnect NetScaler appliances from the internet if immediate patching is not possible.
- Disable DTLS on NetScaler appliances if operationally feasible to mitigate CVE-2026-88772.
- Review NetScaler web server configurations for unauthorized changes, specifically unauthorized PHP handlers or aliases in /etc/httpd.conf.
- Audit /etc/httpd.conf for unexpected file extension mappings such as.deb,.sig, or.ico to PHP.
- Check if /bin/sh has been modified to run with setuid root permissions.
- Monitor internal network traffic for unusual tunneling activity originating from NetScaler appliances.
- Hunt for the presence of /tmp/.uxdport or /tmp/.uxdlock files associated with SLAPSHOT.