Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT
Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetSc 2026-9-30 08:24:35 Author: thehackernews.com(查看原文) 阅读量:3 收藏

Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe.

The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted government, financial services, technology, education, and legal and professional services sectors.

"Exploitation of CVE-2026-88772 bypasses authentication and triggers an unhandled termination of the NetScaler Packet Processing Engine (NSPPE) to establish initial root-level access," the tech giant said.

The attacks have been observed weaponizing the flaw to deploy a post-exploitation toolkit that includes previously unreported PHP web shells, like WHIPSHOT, that are capable of disguising Base64-encoded command-and-control (C2) payloads within native HTTP headers.

Also put to use is a novel companion Python tunneler dubbed SLAPSHOT designed to proxy traffic into internal networks for reconnaissance and credential theft. In at least one case observed by Google, the threat actor is said to have relayed traffic through this proxy to manually conduct internal reconnaissance and credential theft.

As detailed by watchTowr Labs, CVE-2026-88772 (CVSS score: 9.5) is a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling in the NSPPE component.

"During the initial pre-authentication cryptographic handshake, the NSPPE parses inbound DTLS record structures," Google said. "Analysis of frontline telemetry suggests that transmitting specially malformed or fragmented record headers induces heap memory boundary corruption within the packet engine, diverting control flow to execute arbitrary shellcode with root-level operating system privileges on the underlying FreeBSD platform."

Following successful exploitation, a web shell payload is self-installed by modifying target httpd.conf files to handle Debian software package format (.deb) files as PHP scripts, paving the way for the deployment of WHIPSHOT and SLAPSHOT. This is accomplished by means of the initial installer.

This configuration change made it possible for the adversary to stage web shells with deceptive file type extensions in "/netscaler/gui/vpn/scripts/linux," Google's cybersecurity division added.

In other cases, the threat actor has been observed implementing a covert configuration hook that disguises web shell execution as image requests and registers signature (.sig) files as executable PHP scripts after enabling the mod_php engine.

The configuration also maps incoming HTTP requests ending in ".ico" under "/vpn/media/" directly to a corresponding ".sig" file with the same base name inside "/var/netscaler/gui/vpn/scripts/linux/."

"For example, clients accessing /vpn/media/e6ee7c85.ico would be served by the dropped PHP web shell e6ee7c85.sig," Google said. "In at least one case, web server access logs showed GET requests returning HTTP 404 responses, but exhibiting elevated processing durations and multi-kilobyte response sizes."

"In subsequent days, the actor attempted access to non-existent .sig files, which generated missing-file errors in httperror-vpn logs implying the files were not there. This may be an indication of attackers managing similar web shells in multiple compromised environments."

The attack chain then progresses to establishing persistent root-level execution for its web shells by leveraging the installer web shells to alter the permissions of "/bin/sh," and then initiate a full NetScaler appliance reboot.

The lightweight PHP web shells, which are dressed up as .deb and .sig files, offer direct command execution and automated appliance persistence. One such web shell is WHIPSHOT, which extracts Base64-encoded commands and payloads from HTTP headers, executes them, and returns the results.

SLAPSHOT, a TCP tunneling tool written in Python, functions as an internal network bridge that accepts commands from WHIPSHOT and forwards arbitrary TCP streams to internal hosts with the goal of facilitating internal reconnaissance, lateral movement, and credential harvesting.

If no active sessions or commands are received within 10 minutes, the malware removes its port and lock files, and terminates its process to cover its tracks and minimize forensic traces.

"This campaign underscores the continued targeting of edge devices to gain initial access to victim networks," Google said. "These appliances—including Application Delivery Controllers, VPN gateways, and firewalls—remain  attractive targets because they are exposed to the internet, sit outside the reach of endpoint detection and response (EDR) tools, and often store or process credentials that can be used to move deeper into the network."

The development comes as GreyNoise said it began seeing additional malicious cyber activity linked to the exploitation of CVE-2026-88771 and CVE-2026-88772 beginning September 28, 2026, around 8:30 a.m. EDT, followed by a significant surge that same day around 10:30 p.m. EDT.

"What started as mass reconnaissance yesterday has now evolved into full-on mass exploitation across a multitude of independent actors and campaigns," the GreyNose team told The Hacker News. "We are observing wide-scale web shell and malware deployment for the primary purposes of botnet recruitment and access brokering."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2026/09/attackers-exploit-netscaler-flaw-for.html
如有侵权请联系:admin#unsafe.sh