Skip to main content
Emerging ThreatsMalware & Ransomware

Hackers Exploit Citrix Zero-Day to Deploy Web Shells, Malware

Network operations center interior with blurred laptop screen, hinting at concern, under daylight through tall windows.

GreyNoise’s telemetry caught a probe on September 24 that attempted to modify /bin/sh and install a hidden PHP web shell — three days before Citrix publicly disclosed two NetScaler zero-days. That early activity presaged a wider campaign in which attackers used the newly disclosed CVE-2026-88771 and CVE-2026-88772 to gain root access, deploy web shells, and tunnel into internal networks.

How CVE-2026-88771 and CVE-2026-88772 are being exploited

Citrix disclosed the two flaws — CVE-2026-88771 and CVE-2026-88772 — after administrators reported private warnings from IT suppliers, CERTs, and national cybersecurity agencies. CVE-2026-88771 is described as an unauthenticated remote code execution flaw affecting all NetScaler ADC and Gateway deployments. CVE-2026-88772 is a DTLS-enabled memory overflow vulnerability that can lead to remote code execution or denial of service.

Mandiant and Google telemetry link active exploitation to CVE-2026-88772 in particular. As Mandiant relays Google Threat Intelligence Group’s analysis: "While Google Threat Intelligence Group does not possess exploit code, analysis of frontline telemetry suggests that transmitting specially malformed or fragmented record headers induces heap memory boundary corruption within the packet engine, diverting control flow to execute arbitrary shellcode with root-level operating system privileges on the underlying FreeBSD platform." That NSPPE (NetScaler Packet Processing Engine) termination and memory corruption can give attackers root-level control of vulnerable appliances.

WHIPSHOT and SLAPSHOT: web shells and tunneling malware

Mandiant says attackers deployed two previously undocumented malware families in these intrusions. WHIPSHOT is a PHP web shell disguised as a Debian package and stored in the NetScaler VPN scripts directory. It functions as an HTTP proxy for SLAPSHOT and can extract and launch embedded Python payloads. SLAPSHOT is a Python-based TCP tunneling tool that bridges the compromised NetScaler appliance and internal hosts, accepting commands from WHIPSHOT to open connections, transfer data, and close sessions.

Google observed attackers use the WHIPSHOT/SLAPSHOT proxy to manually conduct reconnaissance and steal credentials. Mandiant also notes SLAPSHOT can terminate itself after inactivity, reducing its visibility to defenders.

Techniques used to hide web shells and maintain root

Researchers documented a consistent set of post-exploitation techniques. Attackers installed PHP web shells in unusual locations (for example, a file named .ctxs.receiver under /var/netscaler/logon/LogonPoint/custom/) and altered the NetScaler web server configuration (/etc/httpd.conf) so non-executable file extensions would be processed as PHP. Observed variations include mapping .deb files, .sig files, .ico images under /vpn/media/, and CSS file names such as receiver.min.css to hidden PHP handlers so malicious requests resembled benign downloads or image requests.

Some web shells returned fake HTTP 404 responses when executing commands. To preserve root execution after initial privilege gain, attackers changed permissions on /bin/sh to set the setuid bit so subsequent commands run with elevated privileges. They also rebooted appliances or restarted the web server to apply configuration changes.

Indicators defenders should hunt for

  • Presence of the .ctxs.receiver file or similarly named PHP files in NetScaler directories.
  • Unauthorized Alias or AliasMatch entries in /etc/httpd.conf that map non-PHP extensions (.deb, .sig, .ico, .css) to PHP handlers.
  • Changes to /bin/sh permissions that set the executable’s setuid bit.
  • Unexpected NSPPE crashes or appliances terminating packet processing.
  • Suspicious files in /tmp such as /tmp/.uxdport or /tmp/.uxdlock associated with SLAPSHOT and nohup-launched Python processes or Base64-encoded payloads.
  • Connections from observed source IPs such as 149.104.78.141 and other unusual inbound activity to exposed NetScaler gateways.

Citrix response and mitigations recommended by Mandiant

Citrix confirmed both vulnerabilities had been exploited against unmitigated NetScaler deployments and released security updates on Sunday. Some researchers have dubbed the pair "PitScaler." watchTowr verified exploitation in the wild and reported Citrix was preparing patches.

Mandiant advises organizations to prioritize installing Citrix’s latest NetScaler security updates, calling patching the only way to address both flaws. For organizations that cannot immediately patch, Mandiant recommends disabling DTLS where operationally feasible and blocking inbound UDP/443 upstream when DTLS is not required — mitigations that Google warns apply only to CVE-2026-88772 and do not protect against CVE-2026-88771.

What this means for government, financial services, and education

Mandiant attributes impact to organizations in North America and Europe across government, financial services, education, legal, and professional services sectors. For government networks and financial services — where NetScaler appliances often sit at the Internet edge and protect sensitive assets — the combination of unauthenticated RCE and tunneling malware presents a clear risk of credential theft and lateral movement. Educational institutions and professional services, likewise, must hunt for the specific indicators above and prioritize rapid patching to prevent persistent, hard-to-detect footholds.

Patching remains the definitive remedy: Mandiant states installing Citrix’s updates is the only way to address both CVE-2026-88771 and CVE-2026-88772. Until appliances are updated, defenders must look for the specific indicators of compromise and apply the limited mitigations for CVE-2026-88772 where appropriate.

Original reporting