Mandiant Details Active Exploitation of Citrix NetScaler Zero-Days and Defense Measures

Summary
Mandiant and Google GTIG describe active exploitation of two Citrix NetScaler zero-days, including custom web shells and a tunneler used for persistence, internal reconnaissance, and credential theft, with detection and remediation guidance.
Key points
- CVE-2026-88772 has been exploited since at least early September; CVE-2026-88771 is also reportedly under active exploitation. Organizations in North America and Europe were likely affected.
- CVE-2026-88772 exploitation uses malformed or fragmented DTLS records to bypass authentication and gain root-level access on NetScaler appliances.
- Attackers altered web server configuration to run PHP web shells disguised as non-script files and set the SUID bit on /bin/sh for persistent root access.
- The WHIPSHOT PHP shell works with SLAPSHOT, a Python tunneler that proxies traffic into internal networks for reconnaissance and credential theft.
- Mandiant recommends hunting for suspicious configuration changes, shell permissions, staged files, process activity, logs, and outbound connections.
- Citrix fixed builds include NetScaler 14.1-73.37 and 13.1-64.23 or later; Mandiant recommends patching, isolating suspected compromises, and rotating exposed credentials.
Article Details
- Attack Vectors
- Active exploitation of CVE-2026-88772 against internet-facing NetScaler appliances used malformed or fragmented DTLS records over UDP/443. GTIG's telemetry analysis suggests the records corrupted packet-engine heap memory, enabling root-level code execution; GTIG did not possess exploit code.
- Citrix disclosed active exploitation of a second zero-day, CVE-2026-88771. The article does not describe its exploitation method.
- After exploitation, the actor changed httpd.conf to execute PHP web shells disguised as .deb or .sig files. One configuration mapped .ico requests to .sig web shells.
- Web shells received encoded commands through HTTP headers. WHIPSHOT relayed requests to the SLAPSHOT proxy, which could forward TCP traffic to internal hosts.
- Defensive Notes
- Prioritize fixed Citrix builds: NetScaler 14.1-73.37 or later, or NetScaler 13.1-64.23 or later, according to deployment track. DTLS and UDP/443 restrictions address exposure to CVE-2026-88772 but should not be relied on for CVE-2026-88771.
- Investigate DTLSv1.0 SSL_HANDSHAKE_FAILURE events with an internal-error reason, especially when followed by NSPPE termination or pitboss messages.
- Inspect httpd.conf for unauthorized PHP handlers and web-path aliases; check VPN script and asset directories for disguised PHP files, and review web access and error logs for anomalous requests.
- Check for unauthorized SUID permissions on /bin/sh, SLAPSHOT's /tmp/.uxdport and /tmp/.uxdlock files, and anomalous Python processes.
- For suspected compromise, isolate affected appliances, assess high-availability nodes independently, restrict egress, and preserve virtual-appliance memory state when feasible. After patching, revoke sessions and rotate potentially exposed appliance and integration credentials.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 143[.]198[.]7[.]94 | Listed as scanning and staging infrastructure in the article's IOC table. |
| IPV4 | 157[.]254[.]167[.]12 | Listed as infrastructure used for NetScaler exploitation and installation of a basic web-shell backdoor. |
MITRE ATT&CK
T1036.008 · Masquerade File TypeThe actor disguised executable PHP web shells with .deb and .sig extensions and configured the web server to run them.T1059.006 · PythonWHIPSHOT launched the Python-based SLAPSHOT payload through a background Python command.T1070.002 · Clear Linux or Mac System LogsThe article describes an actor regex-based log wiper targeting appliance web-access log entries around web-shell paths.T1071.001 · Web ProtocolsWeb shells received encoded commands through HTTP request headers and returned command output over HTTP.T1090.001 · Internal ProxySLAPSHOT acted as a proxy, forwarding TCP streams from the compromised appliance to internal hosts.T1190 · Exploit Public-Facing ApplicationThe actor exploited CVE-2026-88772 on exposed NetScaler appliances to gain initial root-level access.T1505.003 · Web ShellThe actor installed PHP web shells on NetScaler appliances for subsequent command execution.T1548.001 · Setuid and SetgidInstaller web shells set the SUID bit on /bin/sh to preserve root-level execution from later web requests.
CVE
CVE-2026-88771According to vendor disclosures, threat actors are also actively exploiting a second zero-day vulnerability (CVE-2026-88771).CVE-2026-88772Intelligence Group (GTIG) identified active, in-the-wild exploitation of a zero-day vulnerability (CVE-2026-88772) affecting Citrix NetScaler ADC and NetScaler Gateway appliances.
People
Bella ValdescruzAcknowledged for assistance with the analysis.Bhavesh DhakeAcknowledged for assistance with the analysis.Chris LinklaterAcknowledged for assistance with the analysis.Christopher RomanoAcknowledged for assistance with the analysis.Geoff CarstairsAcknowledged for assistance with the analysis.Greg BlaumAcknowledged for assistance with the analysis.Josh ThackstonAcknowledged for assistance with the analysis.Kimberly GoodyAcknowledged for assistance with the analysis.Lianis OlivaAcknowledged for assistance with the analysis.Matthew QuickAcknowledged for assistance with the analysis.Michael EdieAcknowledged for assistance with the analysis.Omar ElAhdanAcknowledged for assistance with the analysis.Peter UkhanovAcknowledged for assistance with the analysis.Sagun ChetryAcknowledged for assistance with the analysis.Stuart CarreraAcknowledged for assistance with the analysis.Tyler McLellanAcknowledged for assistance with the analysis.
Malware
SLAPSHOTThe toolkit also includes a novel companion Python tunneler, SLAPSHOT, capable of proxying traffic into internal networks for reconnaissance and credential theft.WHIPSHOTAnalysis of the actor’s post-exploitation toolkit reveals newly discovered custom PHP web shells, such as WHIPSHOT, capable of disguising Base64-encoded command-and-control (C&C) payloads within native HTTP headers.
Vendors
Products
NetScaler ADCactive, in-the-wild exploitation of a zero-day vulnerability (CVE-2026-88772) affecting Citrix NetScaler ADC and NetScaler Gateway appliances.NetScaler Gatewayexploitation of a zero-day vulnerability (CVE-2026-88772) affecting Citrix NetScaler ADC and NetScaler Gateway appliances.NetScaler VPXConfirm that the NetScaler VPX is appropriately segmented and does not share a Layer 2 network with hypervisor management interfaces, such as ESXi vmk0 or vCenter, or other highly sensitive infrastructure tiers.
Tools
Industries
Educationthat organizations in North America and Europe in the government, financial services, technology, education, and legal and professional services sectors were likely impacted by this exploitation campaign, whichFinancial ServicesWe have observed evidence that organizations in North America and Europe in the government, financial services, technology, education, and legal and professional services sectors were likely impacted by thisGovernmentWe have observed evidence that organizations in North America and Europe in the government, financial services, technology, education, and legal and professional services sectors were likely impacted by thislegal and professional servicesNorth America and Europe in the government, financial services, technology, education, and legal and professional services sectors were likely impacted by this exploitation campaign, which has been ongoing since atTechnologyobserved evidence that organizations in North America and Europe in the government, financial services, technology, education, and legal and professional services sectors were likely impacted by this exploitation