Particle.news

Attackers Exploit Citrix NetScaler Flaws to Install Novel Web Shells

Pre-authentication defects let attackers gain root on internet-facing gateways, create tunnels into internal networks, and expose credentials and sensitive systems.

Overview

  • Security firms say exploitation began in early September and remained undetected for weeks before researchers disclosed active attacks and vendors issued fixes.
  • The primary bug, CVE-2026-88772, is a DTLS-handling memory overflow in the NetScaler packet engine that can be triggered before login to run arbitrary code as root on the appliance.
  • Post-exploit activity uses a lightweight PHP web shell called WHIPSHOT and a Python tunneler named SLAPSHOT; attackers hide shells by mapping .deb or .sig files to PHP and by serving them through innocuous .ico requests.
  • Successful intrusions make /bin/sh setuid and reboot appliances to preserve root access, so responders warn that any credentials, keys or certificates handled by an affected gateway should be treated as exposed and rotated after systems are secured.
  • Citrix has released patches and researchers advise patching first, disabling DTLS or blocking inbound UDP/443 when patching is delayed, and preparing for broad opportunistic exploitation as scanning and mass attacks surged on Sept. 28.