Google Warns of Hackers Actively Exploiting Citrix 0-Day Vulnerabilities to Deploy Web Shells

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Google has warned that threat actors are actively exploiting two critical Citrix NetScaler zero-day vulnerabilities to gain root access, install stealthy web shells, and move into victim networks.

The activity has affected organizations in North America and Europe, including government, financial services, technology, education, legal, and professional-services sectors.

Mandiant Consulting and Google Threat Intelligence Group (GTIG) said the campaign has been active since at least early September 2026.

The attackers are abusing CVE-2026-88772, a critical memory-overflow flaw in Citrix NetScaler ADC and NetScaler Gateway appliances, alongside CVE-2026-88771, an unauthenticated remote code execution vulnerability caused by improper input validation.

Citrix assigned both flaws a CVSS score of 9.5 and confirmed active exploitation. CVE-2026-88772 affects appliances with Datagram Transport Layer Security enabled, which is enabled by default on VPN virtual servers.

Google said exploitation bypasses authentication and causes an unhandled termination of the NetScaler Packet Processing Engine, or NSPPE.

This lets attackers gain root-level access to the underlying FreeBSD operating system. After compromising an appliance, the attackers modify the httpd.conf web server configuration to make deceptive file types execute as PHP.

Citrix 0-Day Exploited to Deploy Webshells

In observed intrusions, the threat actors configured .deb package files and .sig signature files as executable PHP scripts. They also used icon aliases so a request for an apparently harmless .ico file could trigger a hidden web shell.

The campaign deploys a newly identified PHP web shell called WHIPSHOT. The malware hides Base64-encoded command-and-control data in legitimate-looking HTTP headers, helping attackers blend malicious traffic into normal web requests.

WHIPSHOT can relay commands and results while returning fake HTTP 404 Not Found responses, potentially misleading administrators reviewing web logs.

Researchers also identified a Python tunneling tool named SLAPSHOT. The malware listens on a local loopback port and proxies arbitrary TCP traffic from the compromised NetScaler device into the internal network.

This capability allows attackers to perform reconnaissance, connect to internal hosts, steal credentials, and support lateral movement. In one intrusion, the operators reportedly used the proxy for manual internal reconnaissance and credential theft.

The attackers also attempted to preserve root-level access by setting the setuid permission bit on /bin/sh. This makes the system shell execute with elevated privileges, even when commands originate from a lower-privileged web-server process. In some cases, the attackers rebooted the appliance or restarted Apache to activate the malicious configuration changes.

Security teams should urgently update affected NetScaler systems. Citrix lists fixed releases including NetScaler 14.1-73.37 and later, as well as NetScaler 13.1-64.23 and later; equivalent fixed FIPS builds are also available.

Administrators should inspect /etc/httpd.conf for suspicious AddHandler, AliasMatch, and PHP directives search VPN script directories for PHP code hidden in .deb or .sig files; and check for /tmp/.uxdport or /tmp/.uxdlock, which may indicate SLAPSHOT activity.

A setuid-enabled /bin/sh, unexpected NSPPE crashes, DTLS handshake failures, and unusual requests to /vpn/media/ or /vpn/scripts/ should be treated as high-priority compromise indicators.

GreyNoise observed attempted exploitation before Citrix publicly disclosed the flaws, including activity from 149.104.78.141 on September 24. The finding highlights the continuing risk posed by internet-facing edge appliances, which often lack endpoint detection coverage while providing direct access to sensitive internal environments.

IOC Type Indicator Security Significance
Exploit traffic UDP/443, DTLSv1.0 Observed CVE-2026-88772 exploit traffic
NetScaler log SSL_HANDSHAKE_FAILURE + DTLSv1.0 Possible malformed exploit traffic
Process crash NSPPE crash Possible exploitation indicator
Watchdog log pitboss NOT restarting NSPPE High-priority correlated signal
HTTP headers HTTP_NSC_LDAP, HTTP_NSC_CLIENTTYPE Web-shell command delivery
HTTP headers HTTP_X_UX, HTTP_X_UX_[0-9]+ WHIPSHOT C2 traffic
URI /vpn/media/*.ico Possible hidden web-shell access
URI /vpn/media/nsgclient.ico Known web-shell alias
Web-shell paths /vpn/scripts/linux/nsginstaller*.deb Malicious installer shell
Web-shell paths /vpn/scripts/linux/nsgclient*.deb Web-shell staging
Web-shell paths /vpn/scripts/linux/*.php Potential PHP web shells
Web-shell e6ee7c85.sig Reported PHP web-shell variant
SLAPSHOT /tmp/.uxdport, /tmp/.uxdlock Tunneling artifacts
Persistence AddHandler ... .deb/.sig Enables PHP execution
Persistence AliasMatch ^/vpn/media/(.+).ico$ Redirects to web shells
Privilege escalation chmod u+s /bin/sh Enables root execution
Commands /bin/httpd -k restart -f /etc/httpd.conf Applies Apache changes
Commands /netscaler/nsshutdown -R Activates persistence
Suspicious process nohup Python + /tmp/.uxd* Possible SLAPSHOT activity
HTTP response Large/slow HTTP 404 Possible hidden web-shell output
Exploitation IP 143.198.7.94 Scanning/staging infrastructure
Exploitation IP 157.254.167.12 NetScaler exploitation activity
Exploitation IP 149.104.78.141 Pre-disclosure exploitation observed
Web-shell path /var/netscaler/logon/LogonPoint/custom/.ctxs.receiver Hidden web shell
Alias filename receiver.min.css Disguised web-shell access
Alias pattern receiver.min.[0-9a-f]+.css Web-shell alias pattern
SHA-256 6f5a2a452a7901323abd21879c6cecccb47c06aeeaccb1b467212f3b11e4b1e7 Reported web-shell hash

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Google Warns of Hackers Actively Exploiting Citrix 0-Day Vulnerabilities to Deploy Web Shells appeared first on Cyber Security News.