Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

The Hacker News by The Hacker News
September 30, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe.

The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted government, financial services, technology, education, and legal and professional services sectors.

“Exploitation of CVE-2026-88772 bypasses authentication and triggers an unhandled termination of the NetScaler Packet Processing Engine (NSPPE) to establish initial root-level access,” the tech giant said.

The attacks have been observed weaponizing the flaw to deploy a post-exploitation toolkit that includes previously unreported PHP web shells, like WHIPSHOT, that are capable of disguising Base64-encoded command-and-control (C2) payloads within native HTTP headers.

Also put to use is a novel companion Python tunneler dubbed SLAPSHOT designed to proxy traffic into internal networks for reconnaissance and credential theft. In at least one case observed by Google, the threat actor is said to have relayed traffic through this proxy to manually conduct internal reconnaissance and credential theft.

As detailed by watchTowr Labs, CVE-2026-88772 (CVSS score: 9.5) is a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling in the NSPPE component.

“During the initial pre-authentication cryptographic handshake, the NSPPE parses inbound DTLS record structures,” Google said. “Analysis of frontline telemetry suggests that transmitting specially malformed or fragmented record headers induces heap memory boundary corruption within the packet engine, diverting control flow to execute arbitrary shellcode with root-level operating system privileges on the underlying FreeBSD platform.”

Following successful exploitation, a web shell payload is self-installed by modifying target httpd.conf files to handle Debian software package format (.deb) files as PHP scripts, paving the way for the deployment of WHIPSHOT and SLAPSHOT. This is accomplished by means of the initial installer.

This configuration change made it possible for the adversary to stage web shells with deceptive file type extensions in “/netscaler/gui/vpn/scripts/linux,” Google’s cybersecurity division added.

In other cases, the threat actor has been observed implementing a covert configuration hook that disguises web shell execution as image requests and registers signature (.sig) files as executable PHP scripts after enabling the mod_php engine.

The configuration also maps incoming HTTP requests ending in “.ico” under “/vpn/media/” directly to a corresponding “.sig” file with the same base name inside “/var/netscaler/gui/vpn/scripts/linux/.”

“For example, clients accessing /vpn/media/e6ee7c85.ico would be served by the dropped PHP web shell e6ee7c85.sig,” Google said. “In at least one case, web server access logs showed GET requests returning HTTP 404 responses, but exhibiting elevated processing durations and multi-kilobyte response sizes.”

“In subsequent days, the actor attempted access to non-existent .sig files, which generated missing-file errors in httperror-vpn logs implying the files were not there. This may be an indication of attackers managing similar web shells in multiple compromised environments.”

The attack chain then progresses to establishing persistent root-level execution for its web shells by leveraging the installer web shells to alter the permissions of “/bin/sh,” and then initiate a full NetScaler appliance reboot.

The lightweight PHP web shells, which are dressed up as .deb and .sig files, offer direct command execution and automated appliance persistence. One such web shell is WHIPSHOT, which extracts Base64-encoded commands and payloads from HTTP headers, executes them, and returns the results.

SLAPSHOT, a TCP tunneling tool written in Python, functions as an internal network bridge that accepts commands from WHIPSHOT and forwards arbitrary TCP streams to internal hosts with the goal of facilitating internal reconnaissance, lateral movement, and credential harvesting.

If no active sessions or commands are received within 10 minutes, the malware removes its port and lock files, and terminates its process to cover its tracks and minimize forensic traces.

“This campaign underscores the continued targeting of edge devices to gain initial access to victim networks,” Google said. “These appliances—including Application Delivery Controllers, VPN gateways, and firewalls—remain  attractive targets because they are exposed to the internet, sit outside the reach of endpoint detection and response (EDR) tools, and often store or process credentials that can be used to move deeper into the network.”

The development comes as GreyNoise said it began seeing additional malicious cyber activity linked to the exploitation of CVE-2026-88771 and CVE-2026-88772 beginning September 28, 2026, around 8:30 a.m. EDT, followed by a significant surge that same day around 10:30 p.m. EDT.

“What started as mass reconnaissance yesterday has now evolved into full-on mass exploitation across a multitude of independent actors and campaigns,” the GreyNose team told The Hacker News. “We are observing wide-scale web shell and malware deployment for the primary purposes of botnet recruitment and access brokering.”



Source link

The Hacker News

The Hacker News

Next Post

Half of Brits struggle to spot AI scams | Computer Weekly

Recommended.

Weibo Announces Fourth Quarter and Fiscal Year 2024 Unaudited Financial Results and Annual Dividend

Weibo Announces Fourth Quarter and Fiscal Year 2024 Unaudited Financial Results and Annual Dividend

March 13, 2025
Sharp rise in AI adoption for cyber defense exposes major governance gap

Sharp rise in AI adoption for cyber defense exposes major governance gap

July 16, 2026

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026
Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026

AWS Pours $6B Into New US Data Center As Amazon’s $220B Spending Goal Unfolds

August 20, 2026
CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

January 8, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio