Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Citrix NetScaler Zero-Days Under Active Attack: Google Uncovers Hidden Web Shell Campaign
Citrix NetScaler Zero-Days Under Active Attack: Google Uncovers Hidden Web Shell Campaign
Read Time:3 Minute, 28 Second

Google’s threat intelligence arm, working alongside Mandiant Consulting, has disclosed an active exploitation campaign against Citrix NetScaler ADC and NetScaler Gateway appliances that has been running since at least early September 2026. The attackers are chaining two critical flaws to seize root-level control of edge devices and quietly install a custom web shell, giving them a long-term foothold inside corporate networks.

Two Critical Flaws, One Devastating Combination

The campaign relies on a pair of vulnerabilities that Citrix rated 9.5 on the CVSS scale. The first, tracked as CVE-2026-88772, is a memory-overflow bug that affects NetScaler appliances running Datagram Transport Layer Security, a setting enabled by default on VPN virtual servers. The second, CVE-2026-88771, is an unauthenticated remote code execution flaw rooted in improper input validation.

According to Google, exploitation of the DTLS flaw sidesteps authentication entirely and forces an abnormal shutdown of the NetScaler Packet Processing Engine, the component responsible for handling network traffic on the appliance. That crash opens a path for attackers to reach the underlying FreeBSD operating system with root privileges — the highest level of access on the box.

A Web Shell Hidden in Plain Sight

Once inside, the intruders reconfigure the appliance’s Apache web server settings so that ordinary-looking files are secretly executed as PHP scripts. In the intrusions Google reviewed, attackers disguised their tools as .deb package files and .sig signature files, and set up icon aliases so that requesting an apparently harmless .ico image would instead trigger a hidden backdoor.

That backdoor, which researchers have named WHIPSHOT, is a PHP-based web shell that smuggles command-and-control traffic inside legitimate-looking HTTP headers using Base64 encoding. To further cover its tracks, WHIPSHOT can respond to investigators with convincing — but fake — HTTP 404 “Not Found” errors, making the compromise harder to spot during a routine log review.

A second tool discovered in the campaign, dubbed SLAPSHOT, is a lightweight Python-based tunneling utility. It listens on a local loopback port and relays arbitrary TCP traffic from the compromised NetScaler device into the broader internal network, effectively turning the appliance into a bridge for deeper reconnaissance, credential theft, and lateral movement.

To make sure they don’t lose their access, the attackers also set the setuid bit on the system’s basic shell binary, which lets that shell run with elevated privileges no matter who invokes it — including a low-privileged web server process. In several cases, the intruders rebooted the appliance or restarted the web server specifically to activate these malicious configuration changes.

Who Has Been Targeted

Google says victims span government agencies, financial services firms, technology companies, educational institutions, and legal and professional-services organizations across North America and Europe. Separately, the threat-monitoring firm GreyNoise reported observing exploitation attempts before Citrix publicly disclosed the flaws, underscoring how far ahead of public awareness the attackers were operating.

The incident is a reminder of a persistent weak spot in enterprise security: internet-facing edge appliances like VPN gateways often sit outside the reach of endpoint detection tools while providing a direct route into sensitive internal systems.

What Defenders Should Do Now

Citrix has shipped fixed builds, including NetScaler 14.1-73.37 and later, and NetScaler 13.1-64.23 and later, along with equivalent FIPS-compliant releases. Security teams that run NetScaler appliances should treat patching as urgent and also hunt for signs of prior compromise, since a patch alone won’t remove an implant that’s already in place. Recommended checks include:

  • Reviewing the appliance’s Apache configuration file for unexpected handler or alias directives tied to PHP execution
  • Searching VPN script directories for disguised PHP code hidden inside .deb or .sig files
  • Checking for suspicious loopback artifacts that may indicate SLAPSHOT tunneling activity
  • Treating unexpected packet-processing-engine crashes, DTLS handshake failures, or unusual requests to VPN media and script paths as high-priority alerts
  • Looking for a shell binary with the setuid bit unexpectedly enabled

Given the severity of the flaws and evidence of exploitation predating public disclosure, organizations running affected NetScaler versions should assume compromise is possible until they’ve completed both patching and a thorough forensic review.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Citrix NetScaler Zero-Days Under Active Attack: Google Uncovers Hidden Web Shell Campaign, use the discussion on Forum.

>> forum community

Comments

Leave a Reply