The attackers behind the Citrix NetScaler zero-day campaign have been hiding their web shells in files dressed up as Debian packages and favicon icons, then tunnelling into victim networks through a custom Python proxy. That is the picture from the original report by Mandiant Consulting and Google Threat Intelligence Group (GTIG), which also says the exploitation has been under way since at least early September, weeks before Citrix disclosed the flaw.
GTIG ties the campaign to CVE-2026-88772, one of two NetScaler zero-days Citrix fixed on September 27 and that CISA added to its Known Exploited Vulnerabilities catalog the same day, as IntelFusions reported. It says organizations in North America and Europe in government, financial services, education, legal and professional services were likely affected.
Root on the appliance before anyone logs in
According to GTIG, the exploit abuses how the NetScaler Packet Processing Engine (NSPPE) handles DTLS records during the pre-authentication handshake, giving code execution as root on the appliance's underlying FreeBSD system. A separate technical analysis by Sina Kheirkhah (@SinSinology) of watchTowr Labs, published the same day, traces the bug to a routine that copies reassembled DTLS fragments into a 35,840-byte buffer without checking whether they fit. A crafted run of 120 records pushes about 173 KB into it, and watchTowr says it turned that overflow into shellcode execution on build 14.1-73.30. DTLS is on by default for VPN virtual servers unless an administrator switched it off, watchTowr notes.
Once inside, the attackers edited the appliance's httpd.conf so the web server would run files ending in .deb or .sig as PHP. In one variant, any request for an icon under /vpn/media/ was quietly mapped to a .sig web shell of the same name. To keep root privileges for later web requests, they set the setuid bit on /bin/sh and rebooted the appliance to apply the changes.
Two new tools, WHIPSHOT and SLAPSHOT
Mandiant recovered several lightweight PHP installer shells, often named variations of "nginstaller", that took Base64-encoded commands from HTTP headers such as HTTP_NSC_LDAP and answered with fake 404 responses. Two new families stand out. WHIPSHOT is a PHP web shell disguised as a Debian package that reassembles commands split across as many as 96 custom HTTP headers and relays them over loopback. SLAPSHOT is a Python TCP tunneler that WHIPSHOT launches from an embedded payload; it lets the operator open connections to internal hosts, and GTIG says at least one intrusion used it for hands-on internal reconnaissance and credential theft.
Patch to 14.1-73.37 or 13.1-64.23, then hunt
Mandiant's first recommendation is the fixed Citrix builds: 14.1-73.37 or later on the 14.1 track and 13.1-64.23 or later on 13.1, with separate FIPS and NDcPP builds. A patch does not evict an implant that is already there, so GTIG also tells defenders to:
- search /etc/httpd.conf for AddHandler, php_flag or AliasMatch lines that make non-script extensions run as PHP;
- look for text or PHP files in the VPN client plug-in and media directories, which should hold only binaries and static assets;
- check whether /bin/sh carries a root setuid bit, and whether /tmp/.uxdport or /tmp/.uxdlock exist;
- review web logs for 404 responses on /vpn/media/ or /vpn/scripts/ paths with unusually large bodies.
Where patching has to wait, GTIG suggests disabling DTLS on internet-facing gateways that do not need it, but stresses this does nothing against the second zero-day, CVE-2026-88771. For confirmed compromises it recommends isolating the node and pausing high-availability sync so a tampered configuration is not copied to the standby. Network indicators in the report include 143[.]198[.]7[.]94 and 157[.]254[.]167[.]12.
The detail worth sitting with is the timeline. If exploitation began in early September, exposed NetScalers spent weeks reachable by an attacker nobody was looking for yet, and Unit 42 counted more than 50,000 of them. For those owners, the hunt matters as much as the patch.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.