Skip to content

Executive Summary

Active exploitation of zero-day vulnerabilities CVE-2026-88772 and CVE-2026-88771 targeting Citrix NetScaler ADC and Gateway appliances was observed in North America and Europe across government, financial services, technology, education, and legal sectors. Exploitation of the first vulnerability allowed actors to bypass authentication and gain root-level access by triggering an unhandled termination of the NetScaler Packet Processing Engine (NSPPE). Post-exploitation involved deploying custom PHP web shells, such as WHIPSHOT, and a Python tunneler, SLAPSHOT, for internal reconnaissance and credential theft. Persistence was established through methods like modifying `httpd.conf` to masquerade file types or utilizing icon aliasing for web shell execution, often involving setting the SUID bit on `/bin/sh`.

Facts Only

* Exploitation of CVE-2026-88772 bypasses authentication and terminates the NSPPE to establish root-level access.
* Exploitation resulted in the creation of custom PHP web shells, such as WHIPSHOT, and a Python tunneler named SLAPSHOT.
* Initial access involved transmitting specially malformed or fragmented DTLS record headers to induce heap memory boundary corruption.
* Persistence methods included modifying `/etc/httpd.conf` to handle non-script file types like `.deb` or `.sig` as PHP scripts via `AddHandler`.
* Web shell execution was achieved by setting the SUID bit on `/bin/sh` (`chmod u+s /bin/sh`) for persistent root-level execution.
* The threat actor used web shells to extract Base64-encoded commands from HTTP headers, execute them via functions like `eval()`, and return results.
* SLAPSHOT acted as a TCP tunneling tool, using a custom binary protocol with actions like 'open', 'push', 'pull', 'exch', and 'close' for internal network bridging.
* Detection strategies involve monitoring specific log artifacts (e.g., SSL\HANDSHAKE\FAILURE), file system changes in VPN script directories, and execution of suspicious Python processes referencing temporary files or lock files.

Full Take

The campaign demonstrates a sophisticated methodology targeting perimeter infrastructure to achieve deep internal access, exploiting the inherent exposure of edge devices that often lack robust endpoint security. The shift from raw memory corruption (CVE-2026-88772) to file system manipulation and service configuration changes underscores an advanced capability where initial exploitation is merely the gateway to a more enduring presence. The use of custom tools like WHIPSHOT and SLAPSHOT, coupled with specific persistence techniques that manipulate the web server's handler configuration (`AddHandler`) and privilege escalation bits (`chmod u+s /bin/sh`), reveals a highly tailored adversary focusing on stealth and evasion within complex appliance environments. The existence of YARA rules specifically targeting file system staging paths, execution patterns, and proprietary tunnel artifacts suggests an established threat intelligence feedback loop operating alongside the initial vulnerability disclosure. The implication is that securing these appliances requires moving beyond simple patching to engineering continuous monitoring around configuration integrity, process lineage, and persistent data placement across the entire stack.
What constitutes resilient defense when the control plane itself becomes the primary vector for persistence? How can organizations effectively balance operational necessity—such as maintaining remote access for critical services like Virtual Apps and Desktops—with the immediate need to isolate a potentially compromised edge device? What responsibility do vendors have in ensuring that remediation guidance translates into actionable, universally applicable controls rather than relying solely on specific fixed build numbers?

From the original · Google Cloud Threat Intelligence

Mandiant Google Threat Intelligence Group Introduction In late September 2026, Mandiant Consulting and Google Threat Intelligence Group (GTIG) identified active, in-the-wild exploitation of a zero-day vulnerability (CVE-2026-88772) affecting Citrix NetScaler ADC and NetScaler Gateway appliances.
Read the full story at cloud.google.com

Sentinel — Human

Confidence

This analysis reads as an authentic forensic report blending zero-day exploitation details with highly specific artifact hunting rules, strongly indicating human origin rather than synthetic generation.

Signals Detected
low severity: Sentence length variance is erratic, shifting between highly technical findings and narrative explanations; presence of deeply specific, non-standard commands suggests human curation rather than pure LLM generation.
low severity: The text moves seamlessly between raw forensic artifacts (log entries, shell commands) and high-level strategic advice (Containment, Remediation), demonstrating a structured, human-driven narrative flow.
low severity: The detailed mapping of exploitation steps (Initial Access -> Foothold -> Persistence) and the subsequent hunting strategies show an integrated, cohesive structure typical of deep threat intelligence reports.
low severity: The presence of highly specific IOCs, custom YARA rules (e.g., G_APT_Backdoorwebshell_WHIPSHOT_1), and precise log parsing targets strongly suggests this is derived from actual incident response analysis rather than pure fabrication.
Human Indicators
The structure mimics a professional security advisory, explicitly citing specific system paths (/etc/httpd.conf, /var/log/messages) and providing actionable, multi-stage hunting instructions based on observed exploitation artifacts.
The inclusion of custom YARA rules with highly specific string matching related to custom malware (WHIPSHOT, SLAPSHOT) indicates a human analyst's creation for threat hunting.
The tone balances alarming technical details with pragmatic, risk-based remediation strategies.
Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances | Huntaegis