Google has warned that threat actors are actively exploiting two critical Citrix NetScaler zero-day vulnerabilities to gain root access, install stealthy web shells, and move into victim networks.
The activity has affected organizations in North America and Europe, including government, financial services, technology, education, legal, and professional-services sectors.
Mandiant Consulting and Google Threat Intelligence Group (GTIG) said the campaign has been active since at least early September 2026.
The attackers are abusing CVE-2026-88772, a critical memory-overflow flaw in Citrix NetScaler ADC and NetScaler Gateway appliances, alongside CVE-2026-88771, an unauthenticated remote code execution vulnerability caused by improper input validation.
Citrix assigned both flaws a CVSS score of 9.5 and confirmed active exploitation. CVE-2026-88772 affects appliances with Datagram Transport Layer Security enabled, which is enabled by default on VPN virtual servers.
Google said exploitation bypasses authentication and causes an unhandled termination of the NetScaler Packet Processing Engine, or NSPPE.
This lets attackers gain root-level access to the underlying FreeBSD operating system. After compromising an appliance, the attackers modify the httpd.conf web server configuration to make deceptive file types execute as PHP.
Citrix 0-Day Exploited to Deploy Webshells
In observed intrusions, the threat actors configured .deb package files and .sig signature files as executable PHP scripts. They also used icon aliases so a request for an apparently harmless .ico file could trigger a hidden web shell.
The campaign deploys a newly identified PHP web shell called WHIPSHOT. The malware hides Base64-encoded command-and-control data in legitimate-looking HTTP headers, helping attackers blend malicious traffic into normal web requests.
WHIPSHOT can relay commands and results while returning fake HTTP 404 Not Found responses, potentially misleading administrators reviewing web logs.
Researchers also identified a Python tunneling tool named SLAPSHOT. The malware listens on a local loopback port and proxies arbitrary TCP traffic from the compromised NetScaler device into the internal network.
This capability allows attackers to perform reconnaissance, connect to internal hosts, steal credentials, and support lateral movement. In one intrusion, the operators reportedly used the proxy for manual internal reconnaissance and credential theft.
The attackers also attempted to preserve root-level access by setting the setuid permission bit on /bin/sh. This makes the system shell execute with elevated privileges, even when commands originate from a lower-privileged web-server process. In some cases, the attackers rebooted the appliance or restarted Apache to activate the malicious configuration changes.
Security teams should urgently update affected NetScaler systems. Citrix lists fixed releases including NetScaler 14.1-73.37 and later, as well as NetScaler 13.1-64.23 and later; equivalent fixed FIPS builds are also available.
Administrators should inspect /etc/httpd.conf for suspicious AddHandler, AliasMatch, and PHP directives search VPN script directories for PHP code hidden in .deb or .sig files; and check for /tmp/.uxdport or /tmp/.uxdlock, which may indicate SLAPSHOT activity.
A setuid-enabled /bin/sh, unexpected NSPPE crashes, DTLS handshake failures, and unusual requests to /vpn/media/ or /vpn/scripts/ should be treated as high-priority compromise indicators.
GreyNoise observed attempted exploitation before Citrix publicly disclosed the flaws, including activity from 149.104.78.141 on September 24. The finding highlights the continuing risk posed by internet-facing edge appliances, which often lack endpoint detection coverage while providing direct access to sensitive internal environments.
| IOC Type | Indicator | Security Significance |
|---|---|---|
| Exploit traffic | UDP/443, DTLSv1.0 | Observed CVE-2026-88772 exploit traffic |
| NetScaler log | SSL_HANDSHAKE_FAILURE + DTLSv1.0 | Possible malformed exploit traffic |
| Process crash | NSPPE crash | Possible exploitation indicator |
| Watchdog log | pitboss NOT restarting NSPPE | High-priority correlated signal |
| HTTP headers | HTTP_NSC_LDAP, HTTP_NSC_CLIENTTYPE | Web-shell command delivery |
| HTTP headers | HTTP_X_UX, HTTP_X_UX_[0-9]+ | WHIPSHOT C2 traffic |
| URI | /vpn/media/*.ico | Possible hidden web-shell access |
| URI | /vpn/media/nsgclient.ico | Known web-shell alias |
| Web-shell paths | /vpn/scripts/linux/nsginstaller*.deb | Malicious installer shell |
| Web-shell paths | /vpn/scripts/linux/nsgclient*.deb | Web-shell staging |
| Web-shell paths | /vpn/scripts/linux/*.php | Potential PHP web shells |
| Web-shell | e6ee7c85.sig | Reported PHP web-shell variant |
| SLAPSHOT | /tmp/.uxdport, /tmp/.uxdlock | Tunneling artifacts |
| Persistence | AddHandler ... .deb/.sig | Enables PHP execution |
| Persistence | AliasMatch ^/vpn/media/(.+).ico$ | Redirects to web shells |
| Privilege escalation | chmod u+s /bin/sh | Enables root execution |
| Commands | /bin/httpd -k restart -f /etc/httpd.conf | Applies Apache changes |
| Commands | /netscaler/nsshutdown -R | Activates persistence |
| Suspicious process | nohup Python + /tmp/.uxd* | Possible SLAPSHOT activity |
| HTTP response | Large/slow HTTP 404 | Possible hidden web-shell output |
| Exploitation IP | 143.198.7.94 | Scanning/staging infrastructure |
| Exploitation IP | 157.254.167.12 | NetScaler exploitation activity |
| Exploitation IP | 149.104.78.141 | Pre-disclosure exploitation observed |
| Web-shell path | /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver | Hidden web shell |
| Alias filename | receiver.min.css | Disguised web-shell access |
| Alias pattern | receiver.min.[0-9a-f]+.css | Web-shell alias pattern |
| SHA-256 | 6f5a2a452a7901323abd21879c6cecccb47c06aeeaccb1b467212f3b11e4b1e7 | Reported web-shell hash |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

