Malware
WHIPSHOT
- First Reported
- Sep 29, 2026
- Latest Reported
- Sep 29, 2026
Reported Context (1)
- Analysis of the actor’s post-exploitation toolkit reveals newly discovered custom PHP web shells, such as WHIPSHOT, capable of disguising Base64-encoded command-and-control (C&C) payloads within native HTTP headers. Mandiant Details Active Exploitation of Citrix NetScaler Zero-Days and Defense Measures
CVE (2)
Malware (1)
People (16)
MITRE ATT&CK (8)
Vendors (1)
Products (3)
Tools (2)
Industries (5)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.