Custom Malware Exploits Critical Citrix NetScaler Flaws in Global Attack Campaign
A zero-day campaign targeting Citrix NetScaler ADC and Gateway devices has compromised government, financial and professional services across North America and Europe using novel malware.
Since at least early September, an unidentified group has been exploiting two critical Citrix NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, to infiltrate government bodies, banks, universities, and legal firms in North America and Europe. The intrusion chain uses custom malware - a PHP-based web shell dubbed WHIPSHOT that hides payloads in HTTP headers, and a Python tunneling tool called SLAPSHOT that proxies traffic to internal hosts.
Analysts recommend that affected organizations first hunt for signs of compromise, such as web shells, before deploying the vendor’s patches, because the malware can retain root privileges even after updates. Citrix released eight advisories with critical 9.5 CVSS scores only after the attacks were underway, prompting criticism of its disclosure timeline. The campaign highlights the growing focus on edge devices like application delivery controllers as entry points for sophisticated threat actors.
Why it matters
Compromised Citrix gateways give attackers direct access to internal networks of critical institutions.
In this story
