Mandiant and GTIG identified active exploitation of CVE-2026-88772 against Citrix NetScaler ADC and NetScaler Gateway, with intrusions using custom tooling to gain root access, persist, and move into internal networks. The campaign deployed WHIPSHOT and SLAPSHOT to hide C2 in HTTP headers, proxy traffic for reconnaissance and credential theft, and abuse modified web server settings, while Citrix also warned that CVE-2026-88771 is being actively exploited. #CVE-2026-88772 #CVE-2026-88771 #CitrixNetScaler #WHIPSHOT #SLAPSHOT
Keypoints
- Active in-the-wild exploitation of CVE-2026-88772 affects Citrix NetScaler ADC and NetScaler Gateway appliances.
- The campaign has been ongoing since at least early September 2026 and appears to have impacted organizations in North America and Europe.
- Initial exploitation bypasses authentication and can lead to root-level access on the underlying FreeBSD platform.
- Attackers deployed custom PHP web shells, including WHIPSHOT, and a Python tunneler named SLAPSHOT.
- WHIPSHOT hides Base64-encoded commands inside HTTP headers and can return spoofed 404 responses to conceal activity.
- SLAPSHOT proxies traffic into internal networks for reconnaissance, credential theft, and other follow-on actions.
- Citrix also disclosed that CVE-2026-88771 is being actively exploited, making patching and containment urgent.
MITRE Techniques
- [T1190 ] Exploit Public-Facing Application â Attackers exploited Citrix NetScaler appliances over UDP/443 and DTLS to gain initial root-level access. (âtransmitting specially malformed or fragmented record headers induces heap memory boundary corruption⌠to execute arbitrary shellcode with root-level operating system privilegesâ)
- [T1133 ] External Remote Services â The appliances exposed remote access services and VPN gateway functionality that attackers targeted as the entry point. (âCitrix NetScaler ADC and NetScaler Gateway appliancesâ)
- [T1505.003 ] Web Shell â Attackers deployed custom PHP web shells such as WHIPSHOT and installer shells to execute commands and maintain access. (âthe deployment of additional custom malware including WHIPSHOT (a PHP web shell)â)
- [T1059.004 ] Command and Scripting Interpreter: Unix Shell â The web shells executed shell commands such as chmod, restart commands, and reboot operations. (âchmod u+s /bin/shâ, âinitiated an appliance rebootâ, ârestart the Apache daemonâ)
- [T1059.006 ] Command and Scripting Interpreter: Python â SLAPSHOT was a Python tunneler launched with python -c to run encoded payloads. (ânohup -c ⌠base64.b64decodeâ)
- [T1071.001 ] Application Layer Protocol: Web Protocols â WHIPSHOT used HTTP headers and HTTP responses to carry commands and tunneled data. (âextracts Base64-encoded commands from the HTTP_NSC_LDAP headerâ)
- [T1090 ] Proxy â SLAPSHOT proxied traffic into internal hosts and WHIPSHOT relayed client requests to the local loopback proxy. (âcapable of proxying traffic into internal networksâ, âestablishes a socket connection to 127.0.0.1â)
- [T1027 ] Obfuscated Files or Information â Commands and payloads were Base64-encoded to hide content in headers and scripts. (âBase64-encoded command-and-control payloadsâ, âBase64-encoded commandsâ)
- [T1105 ] Ingress Tool Transfer â The actor staged and deployed custom malware and web shells onto compromised appliances. (âstaged in files with .deb and .sig extensionsâ)
- [T1053.003 ] Scheduled Task/Job: Cron â Attackers scrubbed references from /etc/crontab to hide persistence and staging paths. (âscrubs references to /vpn/scripts/linux from /etc/crontabâ)
- [T1543.002 ] Create or Modify System Process: Systemd/Service? â Not directly indicated; omitted.
- [T1548.001 ] Abuse Elevation Control Mechanism: Setuid and Setgid â Attackers set the setuid bit on /bin/sh to preserve root execution for later web requests. (âchmod u+s /bin/shâ)
- [T1070.004 ] File Deletion â The actor removed or hid traces by scrubbing logs and installation paths. (âsystematically scrub its installation path from system `/etc/crontab`â)
- [T1211 ] Exploitation for Defense Evasion â Spoofed 404 responses and path-masking helped conceal web shell activity. (âreturns a spoofed HTTP 404 Not Found response codeâ)
Indicators of Compromise
- [IPv4 Address] Scanning and staging infrastructure â 143.198.7.94, 157.254.167.12
- [Network/Transport] Exploit delivery over DTLS on UDP/443 â UDP:443 (DTLSv1.0)
- [HTTP Request Header] Web shell command header used by installer and backdoor variants â HTTP_NSC_LDAP, HTTP_NSC_CLIENTTYPE
- [HTTP Request Header] Chunked Base64 transport headers used by WHIPSHOT â HTTP_X_UX, HTTP_X_UX_[0-9]+
- [URI Path] Masqueraded web-shell access paths â /vpn/media/nsgclient.ico, /vpn/media/*.ico
- [URI Path] Malicious staging locations for PHP web shells â /vpn/scripts/linux/nsginstaller*.deb, /vpn/scripts/linux/nsgclient*.deb, /vpn/scripts/linux/*.php
- [File Path] SLAPSHOT runtime artifacts â /tmp/.uxdport, /tmp/.uxdlock
- [File/Config Path] Compromised web-server configuration and script locations â /etc/httpd.conf, /var/netscaler/gui/vpn/scripts/linux/