Opens in a new tab

Citrix NetScaler zero-day exploited to deploy web shells and tunneling malware

  • Home
  • Blog
  • Citrix NetScaler zero-day exploited to deploy web shells and tunneling malware
NetScaler appliance in a server rack exploited by a Citrix zero-day attack

Defenders running Citrix NetScaler ADC and Gateway appliances now have a concrete path to detect and contain an active exploitation campaign. Two newly disclosed remote code execution flaws, tracked as CVE-2026-88771 and CVE-2026-88772, were abused in the wild to install custom web shells and tunneling malware, gain root access, harvest credentials, and move further into internal networks.

What Citrix disclosed

Citrix disclosed both flaws on a Sunday and confirmed that both had been exploited against unmitigated NetScaler deployments. CVE-2026-88771 is an unauthenticated remote code execution flaw affecting all NetScaler ADC and Gateway deployments. CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service when DTLS is enabled. Researchers informally dubbed the pair “PitScaler.”

How the attacks played out

Cyber threat intelligence firm GreyNoise observed exploitation attempts against a Citrix NetScaler Gateway on September 24, three days before Citrix publicly disclosed the two CVEs. The activity originated from IP address 149.104.78.141 and was flagged by GreyNoise before CVE detections existed.

In those attempts, the threat actor tried to modify /bin/sh to grant a root shell and install a password-protected PHP web shell at /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver. The attacker also tried to modify /etc/httpd.conf so that requests for files that look like CSS files, such as receiver.min.css, would instead open the hidden PHP web shell. GreyNoise is not publishing the full exploit, but recommends defenders hunt for the .ctxs.receiver file, related Alias or AliasMatch entries in httpd.conf, changes to the permissions of /bin/sh, and connections from the observed source IP.

What root-level access looks like

A Mandiant report on CVE-2026-88772 describes how the exploit bypasses authentication and causes the NetScaler Packet Processing Engine (NSPPE) to terminate unexpectedly, handing attackers root-level access. According to Mandiant, transmitting specially malformed or fragmented record headers induces heap memory boundary corruption within the packet engine, which diverts control flow to execute arbitrary shellcode with root-level operating system privileges on the underlying FreeBSD platform.

Mandiant observed attackers installing PHP web shells and rewriting the NetScaler web server configuration so non-executable file extensions would process as PHP. In one intrusion, the attackers modified /etc/httpd.conf so .deb files would execute as PHP, letting web shells run from directories that normally hold NetScaler client software. In other attacks, .sig files were repurposed and requests for .ico images under /vpn/media/ were mapped to malicious PHP files. That setup let web shell requests look like requests for image files or CSS while executing attacker commands through shell_exec() or eval(). Some of the web shells returned fake HTTP 404 responses when executing commands, further disguising the activity.

WHIPSHOT and SLAPSHOT: the two malware families

Mandiant tracks two previously undocumented malware families used in this campaign. WHIPSHOT is a PHP web shell disguised as a Debian package and stored in the NetScaler VPN scripts directory. It acts as an HTTP proxy for SLAPSHOT, extracting Base64-encoded data from HTTP request headers and forwarding it to the tunneling malware running on the compromised appliance. WHIPSHOT also checks whether SLAPSHOT is running and can extract and launch the embedded Python payloads in the background.

SLAPSHOT is a Python-based TCP tunneling tool that bridges the compromised NetScaler appliance and internal devices, letting attackers spread further into the network. It accepts commands from WHIPSHOT, opens connections to internal hosts, sends and receives data over those connections, and closes sessions when finished. Mandiant says attackers used the proxy in at least one intrusion to manually conduct reconnaissance and steal credentials. The malware can also terminate itself after periods of inactivity, which makes it harder to detect.

How attackers kept root after reboot

Although exploitation initially grants root privileges, commands executed by the web shells would normally run under the lower-privileged account used by the NetScaler web servers. To maintain root access, Mandiant says the attackers modified permissions on /bin/sh so commands would run with root privileges. To establish persistent root-level execution for its web shells, the threat actor used lightweight installer web shells to set the setuid bit on the /bin/sh executable. The attacker also rebooted NetScaler appliances or restarted the web server to apply the configuration changes.

Which organizations are affected

Mandiant says the attacks began at least in early September and are believed to have impacted organizations in North America and Europe across the government, financial services, education, legal, and professional services sectors.

What to hunt for

NetScaler ADC and Gateway appliances are attractive targets because they sit on the internet and often sit at the edge of internal networks without the benefit of EDR software. Mandiant says defenders should prioritize installing the latest Citrix security updates and inspect NetScaler appliances for signs of compromise. Specific indicators include unauthorized PHP handlers or aliases in httpd.conf, suspicious .deb or .sig files containing PHP code, unusual HTTP 404 responses, unexpected NSPPE crashes, and the presence of /tmp/.uxdport or /tmp/.uxdlock files associated with SLAPSHOT. Organizations should also check whether /bin/sh has been modified to run with setuid root permissions and look for suspicious Python processes launched with nohup or containing Base64-encoded payloads.

Mitigations and the limits of disabling DTLS

For organizations that cannot immediately patch, Mandiant recommends disabling DTLS where operationally feasible and blocking inbound UDP/443 upstream when DTLS is not required. However, Mandiant warns that these mitigations apply only to CVE-2026-88772 and do not protect against the separately exploited CVE-2026-88771 vulnerability. Mandiant says installing the latest NetScaler security updates is the only way to address both flaws.

FAQ

What is CVE-2026-88772?

CVE-2026-88772 is a memory overflow vulnerability in Citrix NetScaler ADC and Gateway that can lead to remote code execution or denial of service when DTLS is enabled. Citrix confirmed it was exploited in zero-day attacks before a patch was available.

What did the attackers install on compromised NetScaler appliances?

Attackers installed PHP web shells and modified /etc/httpd.conf so non-executable file extensions such as .deb, .sig, .ico, and CSS files would execute as PHP. They also deployed two previously undocumented malware families tracked as WHIPSHOT and SLAPSHOT, a PHP web shell and a Python-based TCP tunneling tool used to pivot into internal networks.

How can defenders tell if a NetScaler appliance was compromised?

Indicators include unauthorized PHP handlers or aliases in httpd.conf, suspicious .deb or .sig files containing PHP code, unusual HTTP 404 responses, unexpected NSPPE crashes, the presence of /tmp/.uxdport or /tmp/.uxdlock files associated with SLAPSHOT, modifications to /bin/sh that set the setuid bit, and suspicious Python processes launched with nohup or containing Base64-encoded payloads.

Does disabling DTLS fully protect against these attacks?

No. Disabling DTLS and blocking inbound UDP/443 protects only against CVE-2026-88772 and does not address CVE-2026-88771, which has also been exploited. Installing the latest Citrix security updates is the only mitigation that addresses both flaws.


This article summarizes reporting from bleepingcomputer.com.

← All Articles