Since at least early September 2026, attackers have taken root-level control of Citrix NetScaler appliances without a password. Mandiant and Google Threat Intelligence Group (GTIG) traced the break-ins to a Citrix NetScaler zero-day, CVE-2026-88772. In their new report on the campaign, the researchers describe custom web shells hidden behind fake image requests.
At a Glance
| Actor | Unidentified; no public attribution |
| Activity | Zero-day exploitation, web shells, network tunneling, credential theft |
| Targets | Government, finance, technology, education, and legal firms in North America and Europe |
| Scale | Not disclosed; GTIG says organizations were “likely impacted” |
| Law enforcement | No arrests or charges announced |
| Sources | Mandiant and GTIG; Citrix security bulletin |
TL;DR
An unknown actor is exploiting CVE-2026-88772 to gain root access on NetScaler ADC and Gateway devices. The attackers then install hidden web shells and a proxy to reach internal networks. Citrix has released fixes, and a second zero-day is also under attack.
What Happened
A Crash That Opens the Door
The flaw lives in NetScaler’s packet engine. Attackers send malformed DTLS traffic over UDP port 443 during the first handshake. According to GTIG, this likely corrupts heap memory and runs attacker code with root rights. The packet engine then crashes, and that crash leaves traces in the logs.
Citrix’s security bulletin for CVE-2026-88771 through CVE-2026-88778 adds a second concern. The vendor reports that attackers are also exploiting CVE-2026-88771.
Web Shells Disguised as Icons
Next, the attackers change the appliance’s web server settings. In some cases, they make files ending in .deb or .sig run as PHP code. In others, requests for harmless .ico icon files quietly run a web shell instead. The shells even return fake “404 Not Found” errors to look like broken links.
To keep root access, the actors also change permissions on the system shell. After that, they reboot the device or restart its web server.
WHIPSHOT and SLAPSHOT
Mandiant found two new tools. WHIPSHOT is a PHP web shell that hides encoded commands inside normal HTTP headers. SLAPSHOT is a Python tunneler that forwards traffic into the internal network. In one intrusion, the actor used this proxy “to manually conduct internal reconnaissance and credential theft.”
Who Is Behind It
GTIG has not named or attributed the actor. The report ties the activity to one campaign based on shared tools and methods. However, it gives no link to a known group or country. Missing web shell files across several victims may suggest the actor manages many compromised systems at once.
Impact and Scale
Mandiant has not published a victim count. Instead, it says organizations across five sectors were “likely impacted.” The risk goes beyond the appliance itself. NetScaler devices often hold LDAP, RADIUS, and admin credentials. As GTIG explains, edge devices “sit outside the reach of endpoint detection and response (EDR) tools.” Notably, such flaws made up about half of enterprise zero-days in 2025.
How to Stay Protected
Mandiant urges teams to patch first. Other steps include:
- Upgrade to NetScaler 14.1-73.37 or 13.1-64.23 and later. FIPS builds are also available.
- If patching must wait, disable DTLS and block inbound UDP/443 at the upstream firewall. This does not fix CVE-2026-88771.
- Check the web server config for PHP handlers tied to odd file types.
- Alert on DTLS handshake failures followed by packet engine crashes.
- Run Citrix’s IOC Scanner and isolate any appliance that shows signs of compromise.
- After patching, rotate admin, LDAP, RADIUS, SSH, and TLS secrets. End all active sessions.
GTIG expects more of the same: “We expect threat actors to continue to exploit vulnerabilities in edge devices.” In short, treat every Citrix NetScaler zero-day as urgent, and hunt for intrusions even after you patch.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!