Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services
Two questions remain: who is abusing the CVEs? And why did Citrix take so long to disclose?
The public still doesn’t know who is abusing a critical Citrix vulnerability exploited as a zero-day weeks before disclosure, but we now know that the unknown digital intruders have used CVE-2026-88772 to break into government agencies, financial services firms, education organizations, and legal and professional services sectors across North America and Europe.
And everyone agrees that the vendor took way too long to disclose the security holes.
GreyNoise said it spotted an attempt to exploit CVE-2026-88771 against a Citrix NetScaler Gateway on September 24. Google researchers, meanwhile, said the CVE-2026-88772 campaign has been ongoing “since at least early September.”
REG AD
“Why Citrix took so long to disclose these vulnerabilities is a question only Citrix can answer,” Benjamin Harris, founder and CEO of exposure management firm watchTowr, told The Register.
REG AD
Citrix did not respond to our questions about this.
“The vulnerabilities were discovered during incident response and forensic investigations at organizations already compromised, meaning both the exploitation and Citrix’s awareness of it predated public disclosure,” Harris said. “Citrix has a history of delaying the publication of vulnerabilities, even when they’re being exploited in the wild and affecting customers.”
So if you use Citrix NetScaler ADC and NetScaler Gateway appliances, and haven’t already applied the security updates, do that ASAP. But first, check your systems for signs of compromise, warns Mandiant Consulting CTO Charles Carmakal.
“Given the active exploitation, NetScaler customers should prioritize examining their systems for compromise *before* upgrading/patching,” Carmakal said on LinkedIn. “If you find evidence of web shells or other malicious files, please preserve evidence and investigate the scope of the compromise. Patching alone may not eradicate the threat actor from your environment.”
No attribution - yet
Citrix disclosed eight CVEs on Sunday with the worst of the bunch – CVE-2026-88771 and CVE-2026-88772 – earning critical 9.5 CVSS scores. “Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed,” the vendor said.
CVE-2026-88771 can allow an unauthenticated attacker to execute arbitrary commands remotely. CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service when DTLS is enabled, as it is by default on VPN virtual servers.
But by the time Citrix issued security advisories and warned customers about the vulnerabilities, they were already under attack.
REG AD
“No attribution has been made public, and we have yet to identify a clear trend among targets by industry or organization size,” Harris said. “Historically, NetScaler vulnerabilities have been exploited by both state-sponsored groups and ransomware operators.”
WatchTowr on Tuesday published a technical writeup about CVE-2026-88772, plus a detection artifact generator for Citrix users to determine if they are vulnerable and to help with remediation.
Also on Tuesday, Google’s threat intel businesses provided additional details about the exploitation campaign’s targets and the attacker’s custom malware.
“We have observed evidence that organizations in North America and Europe in the government, financial services, education, legal and professional services sectors were likely impacted by this exploitation campaign, which has been ongoing since at least early September,” Google Threat Intelligence Group and Mandiant said in an advisory.
Custom malware
After analyzing the intruder’s post-exploit toolkit, the malware hunters found never-before-seen malware used to establish persistent root access and proxy traffic into internal corporate networks.
The custom malware includes WHIPSHOT, a PHP web shell, and SLAPSHOT, a TCP tunneling tool written in Python.
WHIPSHOT is disguised as a Debian package and hides Base64-encoded command-and-control payloads in native HTTP headers. It functions as an HTTP transport bridge for SLAPSHOT, which accepts commands from WHIPSHOT and forwards arbitrary TCP streams to internal hosts.
REG AD
Supported commands include:
open, which establishes an outbound TCP socket to a target host and port.
push, which writes data to an open session.
pull, which polls and reads data from an open session socket.
exch, which sends and receives command-and-control data to and from an open session socket.
close, which terminates a specified network session.
ping, which performs a basic health-check verification.
“In at least one observed intrusion, the threat actor routed traffic through this proxy to manually conduct internal reconnaissance and credential theft,” the threat intel teams noted.
Google did not immediately respond to The Register’s questions about the campaign, including how many exploitation attempts and successful intrusions its threat hunters observed. Its advisory notes that the Citrix campaign “underscores the continued targeting of edge devices to gain initial access to victim networks, a trend that GTIG has tracked across a range of threat actors.”
Security and networking vulnerabilities accounted for about half of enterprise-related zero-days in 2025, according to Google’s count.
Attackers love edge devices - application delivery controllers, VPN gateways, and firewalls - because they provide direct access from the open internet to corporate networks, allowing attackers to bypass endpoint detection tools and other security layers.
NetScaler, in particular, is notoriously buggy. Attackers exploited another critical NetScaler vuln in March. A year earlier, Citrix disclosed multiple zero-days in the same product. ®
KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.