Back
New malware WHIPSHOT, SLAPSHOT found in Citrix 0-day attacks on govt, banks
SiTech AI Team3 წთ. საკითხავი

New malware WHIPSHOT, SLAPSHOT found in Citrix 0-day attacks on govt, banks

Attackers behind the Citrix NetScaler 0-day campaign targeted government agencies, banks, education and legal services in North America and Europe, per The Register. Google and Mandiant found never-before-seen malware, WHIPSHOT and SLAPSHOT.

Unknown intruders used a Citrix NetScaler zero-day, CVE-2026-88772, to break into government agencies, financial services firms, education organizations and legal and professional services across North America and Europe, The Register reported on September 29.

Google Threat Intelligence Group and Mandiant analyzed the attacker’s post-exploitation toolkit and found two never-before-seen malware families: WHIPSHOT and SLAPSHOT. In their assessment the campaign has been running since at least early September.

WHIPSHOT and SLAPSHOT

WHIPSHOT is a PHP web shell disguised as a Debian package. It hides Base64-encoded command-and-control (C2) payloads inside native HTTP headers and acts as an HTTP transport bridge for SLAPSHOT.

SLAPSHOT is a TCP tunneling tool written in Python. It accepts commands from WHIPSHOT and forwards arbitrary TCP streams to internal hosts. Supported commands include open (establish an outbound TCP socket), push (write data into an open session), pull (read data back), exch (exchange C2 data), close (terminate a session) and ping (a basic health check).

In at least one observed intrusion, the threat actor routed traffic through this proxy to manually conduct internal reconnaissance and credential theft, Google said.

Victims and attribution

According to the Google and Mandiant advisory, likely victims include organizations in the government, financial services, education, and legal and professional services sectors in North America and Europe.

No attribution has been made public. watchTowr founder and CEO Benjamin Harris told The Register there is no clear trend among targets by industry or organization size. “Historically, NetScaler vulnerabilities have been exploited by both state-sponsored groups and ransomware operators,” he said.

Delayed disclosure and advice

GreyNoise said it spotted an attempt to exploit CVE-2026-88771 against a Citrix NetScaler Gateway on September 24, while Google said the CVE-2026-88772 campaign has been ongoing since at least early September. Citrix disclosed eight CVEs at once; CVE-2026-88771 and CVE-2026-88772 carry critical 9.5 CVSS scores.

Harris said the flaws were discovered during incident response and forensic investigations at organizations already compromised, meaning both the exploitation and Citrix’s awareness of it predated public disclosure. “Why Citrix took so long to disclose these vulnerabilities is a question only Citrix can answer,” he said.

Mandiant Consulting CTO Charles Carmakal advised NetScaler customers to examine systems for signs of compromise before upgrading or patching. If they find web shells or other malicious files, they should preserve evidence and investigate the scope of the compromise, he said, adding that patching alone may not eradicate the threat actor from an environment.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.