Mandiant Details Active Exploitation of Citrix NetScaler Zero-Days and Defense Measures

· Original article ↗

Summary

Mandiant and Google GTIG describe active exploitation of two Citrix NetScaler zero-days, including custom web shells and a tunneler used for persistence, internal reconnaissance, and credential theft, with detection and remediation guidance.

Key points

  • CVE-2026-88772 has been exploited since at least early September; CVE-2026-88771 is also reportedly under active exploitation. Organizations in North America and Europe were likely affected.
  • CVE-2026-88772 exploitation uses malformed or fragmented DTLS records to bypass authentication and gain root-level access on NetScaler appliances.
  • Attackers altered web server configuration to run PHP web shells disguised as non-script files and set the SUID bit on /bin/sh for persistent root access.
  • The WHIPSHOT PHP shell works with SLAPSHOT, a Python tunneler that proxies traffic into internal networks for reconnaissance and credential theft.
  • Mandiant recommends hunting for suspicious configuration changes, shell permissions, staged files, process activity, logs, and outbound connections.
  • Citrix fixed builds include NetScaler 14.1-73.37 and 13.1-64.23 or later; Mandiant recommends patching, isolating suspected compromises, and rotating exposed credentials.

Article Details

Attack Vectors
  • Active exploitation of CVE-2026-88772 against internet-facing NetScaler appliances used malformed or fragmented DTLS records over UDP/443. GTIG's telemetry analysis suggests the records corrupted packet-engine heap memory, enabling root-level code execution; GTIG did not possess exploit code.
  • Citrix disclosed active exploitation of a second zero-day, CVE-2026-88771. The article does not describe its exploitation method.
  • After exploitation, the actor changed httpd.conf to execute PHP web shells disguised as .deb or .sig files. One configuration mapped .ico requests to .sig web shells.
  • Web shells received encoded commands through HTTP headers. WHIPSHOT relayed requests to the SLAPSHOT proxy, which could forward TCP traffic to internal hosts.
Defensive Notes
  • Prioritize fixed Citrix builds: NetScaler 14.1-73.37 or later, or NetScaler 13.1-64.23 or later, according to deployment track. DTLS and UDP/443 restrictions address exposure to CVE-2026-88772 but should not be relied on for CVE-2026-88771.
  • Investigate DTLSv1.0 SSL_HANDSHAKE_FAILURE events with an internal-error reason, especially when followed by NSPPE termination or pitboss messages.
  • Inspect httpd.conf for unauthorized PHP handlers and web-path aliases; check VPN script and asset directories for disguised PHP files, and review web access and error logs for anomalous requests.
  • Check for unauthorized SUID permissions on /bin/sh, SLAPSHOT's /tmp/.uxdport and /tmp/.uxdlock files, and anomalous Python processes.
  • For suspected compromise, isolate affected appliances, assess high-availability nodes independently, restrict egress, and preserve virtual-appliance memory state when feasible. After patching, revoke sessions and rotate potentially exposed appliance and integration credentials.

Indicators of compromise

TypeIndicatorContext
IPV4143[.]198[.]7[.]94Listed as scanning and staging infrastructure in the article's IOC table.
IPV4157[.]254[.]167[.]12Listed as infrastructure used for NetScaler exploitation and installation of a basic web-shell backdoor.

MITRE ATT&CK

CVE

People

Malware

Vendors

Products

Tools

Industries

Related Articles