Skip to main content
Emerging ThreatsMalware & Ransomware

Citrix Zero-Day Exploits Target Gov't, Finance Firms with Custom Malware

Government agency office interior with computer workstations and subtle IT equipment in background.

“Why Citrix took so long to disclose these vulnerabilities is a question only Citrix can answer,” Benjamin Harris told The Register — a blunt observation that now frames an active exploitation campaign hitting government agencies, banks, education institutions and legal and professional services across North America and Europe.

What Citrix disclosed and what was already happening

Citrix issued advisories on Sunday that addressed eight CVEs, flagging two as critical: CVE-2026-88771 and CVE-2026-88772, both rated 9.5 CVSS. The vendor warned that “Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed.” According to the advisory and subsequent reporting, CVE-2026-88771 allows an unauthenticated attacker to execute arbitrary commands remotely, while CVE-2026-88772 is a memory overflow that can produce remote code execution or denial-of-service when DTLS is enabled — a setting the vendor says is enabled by default on VPN virtual servers.

Timeline signals: scanning and ongoing exploitation

External observers put exploitation weeks ahead of public notice. GreyNoise reported spotting an attempt to exploit CVE-2026-88771 against a Citrix NetScaler Gateway on September 24. Google Threat Intelligence Group and Mandiant reported the CVE-2026-88772 campaign has been ongoing “since at least early September.” WatchTowr’s founder Benjamin Harris told The Register that the vulnerabilities were discovered during incident response at already-compromised organizations, meaning exploitation and Citrix’s awareness “predated public disclosure.”

Google and Mandiant: custom malware, proxying, and credential theft

After gaining access via the NetScaler flaws, threat hunters from Google and Mandiant identified a bespoke post-exploit toolkit. The tools include WHIPSHOT — a PHP web shell disguised as a Debian package that hides Base64-encoded command-and-control payloads in native HTTP headers — and SLAPSHOT, a Python-based TCP tunneling tool that uses WHIPSHOT as an HTTP transport bridge.

SLAPSHOT supports a small set of commands that together establish and operate arbitrary TCP proxy sessions: open, push, pull, exch, close and ping. “In at least one observed intrusion, the threat actor routed traffic through this proxy to manually conduct internal reconnaissance and credential theft,” the advisory states.

Guidance from incident responders: check before you patch

Responders warned that patching alone may not eject intruders. Mandiant Consulting CTO Charles Carmakal posted on LinkedIn urging NetScaler customers to “prioritize examining their systems for compromise before upgrading/patching.” Carmakal advised preserving evidence if web shells or other malicious files are found and investigating the scope of compromise, because “Patching alone may not eradicate the threat actor from your environment.”

On Tuesday, watchTowr published a technical writeup on CVE-2026-88772 and released a detection artifact generator for Citrix users to test vulnerability and assist remediation.

Observed targets and the strategic appeal of edge devices

Google Threat Intelligence Group and Mandiant said they observed likely impacts in organizations across government, financial services, education, legal and professional services in North America and Europe. The advisory framed the campaign as part of a broader trend: attackers continue to target edge devices — application delivery controllers, VPN gateways and firewalls — because those systems provide direct access from the internet to internal networks and can bypass endpoint detection.

The reporting notes a recent history of serious NetScaler vulnerabilities: attackers exploited another critical NetScaler flaw in March, and Citrix disclosed multiple zero-days in the same product the year before.

What this means for technologists, procurement leaders, and regulators

  • Technologists and security teams: prioritize forensic checks for web shells and other indicators of compromise before applying updates; preserve evidence and investigate the extent of any intrusions, since patching may not remove persistent implants such as WHIPSHOT and SLAPSHOT.
  • Procurement and operations leaders: account for the continued targeting of edge devices when planning vendor risk and patch management timelines; note that vendors may learn of active exploitation during customer incident response, as watchTowr described in this campaign.
  • Regulators and risk officers: the campaign highlights how delays between discovery and public disclosure can leave organizations exposed; as Benjamin Harris put it, “Why Citrix took so long to disclose these vulnerabilities is a question only Citrix can answer.”

The immediate, concrete tasks are clear: NetScaler ADC and NetScaler Gateway customers who have not applied the updates should do so, but only after or in parallel with active checks for compromise; defenders should look for WHIPSHOT and SLAPSHOT indicators and preserve forensic evidence where found. At the same time, the campaign underscores a recurring pattern — edge devices repeatedly appear as initial access vectors — and raises a practical question for vendors and customers alike about how quickly discovered, actively exploited bugs move from incident-response rooms into public advisories.

Source: The Register