VMTech
Discuss a project →

NetScaler flaw used to install WHIPSHOT and SLAPSHOT

NetScaler flaw used to install WHIPSHOT and SLAPSHOT

Mandiant Consulting and Google Threat Intelligence Group (GTIG) observed unknown threat actors exploiting CVE-2026-88772 in Citrix NetScaler ADC and NetScaler Gateway appliances during September 2026. The vulnerability, rated CVSS 9.5, was used to obtain initial root-level access and deploy the previously unreported WHIPSHOT web shell and the SLAPSHOT Python tunneler.

The activity affected organizations in North America and Europe across government, financial services, technology, education, and legal and professional services. GreyNoise also reported additional malicious activity tied to CVE-2026-88771 and CVE-2026-88772 from September 28, followed later that day by a substantial rise in exploitation.

DTLS handling creates a pre-authentication route to root

watchTowr Labs described CVE-2026-88772 as a memory-overflow issue in Datagram Transport Layer Security handling within the NetScaler Packet Processing Engine, or NSPPE. During the initial pre-authentication cryptographic handshake, the component processes inbound DTLS record structures.

GTIG said specially malformed or fragmented record headers can cause heap-memory boundary corruption in the packet engine. That corruption can divert control flow to arbitrary shellcode running with root-level operating-system privileges on the appliance’s underlying FreeBSD platform.

The incident highlights a recurring edge-device risk: root compromise beyond exposed systems illustrates how root-level compromise can extend beyond the initial exposed system when attackers gain powerful execution privileges. Google noted that application delivery controllers, VPN gateways and firewalls are attractive initial-access targets because they are internet-facing, may be outside endpoint detection and response coverage, and often process or store credentials.

Web shells hide behind misleading extensions

After exploitation, an initial installer modifies target httpd.conf files so Debian package-format .deb files are handled as PHP scripts. This lets the actor stage web shells under /netscaler/gui/vpn/scripts/linux while making their file types appear less suspicious.

In other observed cases, the actor enabled the mod_php engine and used a covert configuration hook that registered .sig files as executable PHP scripts. Requests ending in .ico under /vpn/media/ were mapped to matching .sig files in the scripts directory. GTIG observed web-server access logs with GET requests returning HTTP 404 while showing unusually long processing times and multi-kilobyte response sizes.

The installer also alters permissions on /bin/sh and reboots the appliance, establishing persistent root-level execution for the shells. WHIPSHOT extracts Base64-encoded commands and payloads from HTTP headers, executes them, and returns the output.

SLAPSHOT bridges into internal networks

SLAPSHOT accepts commands from WHIPSHOT and forwards arbitrary TCP streams to internal hosts. GTIG observed at least one case in which the proxy was used for manual internal reconnaissance and credential theft. When it receives no active sessions or commands for 10 minutes, the tool removes its port and lock files and terminates, reducing forensic traces.

Organizations using affected NetScaler appliances should apply Citrix’s patches and investigate for unexpected changes to httpd.conf, altered shell permissions, suspicious .deb or .sig files, and anomalous .ico requests. Reviewing long-running 404 responses and internal traffic originating from appliances can help identify the web-shell and tunneling behaviours described in this campaign.

#netscaler#cybersecurity#vulnerability#threatintel
Open analytics
On the site 3 views
min read 4 30.09.2026
Instagram

NetScaler flaw used to install WHIPSHOT and SLAPSHOT

Open the post on Instagram ↗