Back to Intelligence

CVE-2026-88772: WHIPSHOT and SLAPSHOT Web Shells in Active Citrix NetScaler Campaign — Detection and Remediation Guide

SA
Security Arsenal Team
September 30, 2026
14 min read

Mandiant and Google Threat Intelligence Group (GTIG) have published findings on an active, in-the-wild exploitation campaign targeting Citrix NetScaler ADC and NetScaler Gateway appliances. Beginning in late September 2026, threat actors have been exploiting CVE-2026-88772 — a critical vulnerability carrying a CVSS score of 9.5 — to deploy two custom web shells, WHIPSHOT and SLAPSHOT, achieving root-level access on edge appliances that sit directly in the traffic path of authentication, VPN, and application delivery flows.

If your organization operates internet-facing NetScaler infrastructure, treat this as an assumed-breach scenario until proven otherwise. Edge appliances are the highest-value initial access target in any environment, and a 9.5 CVSS flaw with confirmed active exploitation and purpose-built post-exploitation tooling means sophisticated actors have already invested in operationalizing this bug. The window between "vulnerable" and "compromised" is measured in hours, not weeks.

What Happened

In late September 2026, Mandiant and GTIG identified active exploitation of an unpatched vulnerability in Citrix NetScaler ADC and NetScaler Gateway. Post-compromise activity includes deployment of two custom web shells:

  • WHIPSHOT — a lightweight web shell planted on the appliance to provide persistent command execution.
  • SLAPSHOT — a second-stage implant used to escalate and maintain root access on the compromised appliance, enabling the actor to harvest credentials traversing the gateway, inspect decrypted traffic, tamper with authentication flows, and pivot inward.

This pattern is consistent with the last several years of NetScaler targeting: actors exploit an edge-facing flaw, implant a web shell on the appliance (which almost no EDR stack covers), and quietly use the gateway as a credential collection and traffic interception platform. The presence of custom tooling — rather than commodity shells — indicates a resourced actor, likely espionage-motivated, conducting a sustained campaign rather than opportunistic scanning.

Technical Analysis

Affected Products

  • Citrix NetScaler ADC (formerly Citrix ADC) — application delivery controller / load balancer
  • Citrix NetScaler Gateway (formerly Citrix Gateway) — VPN, ICA proxy, and authentication front end

Both product lines share the same underlying FreeBSD-based NSOS operating system and management/web service stack, which is why a single vulnerability classically affects both. Organizations running any of the following exposed functions should assume elevated risk:

  • Gateway (VPN, ICA Proxy, CVPN, RDP Proxy, AAA virtual servers)
  • Management interfaces exposed beyond a restricted management network
  • Load-balanced virtual servers terminating TLS on the appliance

Vulnerability Details

  • CVE ID: CVE-2026-88772
  • CVSS Score: 9.5 (Critical)
  • Exploitation status: Confirmed active exploitation in the wild by Mandiant and GTIG as of late September 2026. This is not theoretical — victimology and post-exploitation tooling have been observed directly.
  • Pre-authentication: Edge-facing NetScaler vulnerabilities with CVSS scores in this range are typically exploitable without authentication against the gateway or virtual server surface. Defenders should operate on that assumption.

Attack Chain (Defender's View)

Based on the Mandiant/GTIG reporting and consistent with prior NetScaler tradecraft, the kill chain looks like this:

  1. Initial access: The actor sends crafted requests to an internet-facing NetScaler virtual server or management web service, exploiting CVE-2026-88772 to achieve code execution in the context of the web service.
  2. Web shell deployment (WHIPSHOT): A web shell is written to a web-accessible directory on the appliance filesystem. On NetScaler, historically abused locations include the portal and GUI content trees (e.g., /netscaler/portal/, /var/vpn/, /var/tmp/netscaler/, and the GUI scripts directories). Web shells in these paths are reachable over HTTP/S, giving the actor a reliable command channel.
  3. Privilege escalation (SLAPSHOT): The second-stage tool is used to obtain and persist root access, frequently abusing the fact that NetScaler web service processes historically run with elevated privileges, or chaining a local escalation.
  4. Persistence: Actors commonly establish persistence via cron jobs, modified rc/startup scripts, or implanting the web shell in directories that survive reboots.
  5. Collection and pivot: With root on the gateway, the actor can harvest session cookies and credentials from authentication flows, access configuration files (ns.conf), extract LDAP bind credentials and certificates/keys, and stage lateral movement into the internal network.

Why This Is Severe

A compromised NetScaler Gateway is not just a compromised server — it is a compromised identity and traffic chokepoint. Everything that authenticates through it, and everything it load-balances or proxies, is within the actor's reach. The blast radius of a single compromised appliance routinely includes domain credentials, session tokens, and a beachhead into the internal network. This is exactly the pattern we have led IR engagements on in prior NetScaler campaigns: by the time the web shell is found, credential theft has typically already occurred, and remediation must include full credential rotation, not just patching.

Detection & Response

The challenge with NetScaler compromises is visibility: the appliances rarely run EDR, logs are frequently not forwarded, and web shells blend into the GUI content tree. Detection therefore requires three parallel efforts: filesystem hunting on the appliance, network telemetry analysis, and log analytics on forwarded syslog/CEF data.

Hunting Priorities

  1. Web shell artifacts: New or recently modified files in web-accessible directories, especially files with scripting extensions (.php, .pl, .cgi, .py, .sh) or files with mismatched timestamps (touch-ed to blend in).
  2. Process anomalies: Shells or system utilities (sh, bash, python, perl, curl, wget, nc, socat) spawned as children of NetScaler web service processes (httpd, nshttpd, nsppe).
  3. Persistence: New cron entries (/var/cron/tabs/, /etc/crontab), modified startup scripts, unexpected entries in ns.conf scheduled tasks.
  4. Outbound connections: Any outbound connection from the appliance that is not a known Citrix licensing/telemetry, AD/LDAP, DNS, NTP, or radius destination. NetScaler appliances have a small, well-defined outbound connection profile — deviations are high-signal.
  5. Authentication anomalies: AAA/LDAP bind failures from unexpected sources, authentication log volume anomalies, and session hijacking indicators in gateway logs.

Sigma Rules

The following rules target the behaviors described above. Note that the two Linux rules require process/file telemetry from the appliance — if your NetScaler logs are only forwarded as syslog, deploy the KQL queries below as your primary detection and use the Sigma rules for any Linux-based monitoring you have on or around the appliance (or for jump hosts that might be used to interact with it).

YAML
---
title: NetScaler Web Process Spawning Shell or System Utility
tid: 6f2a1b90-3c4d-4e5f-9a8b-7c6d5e4f3a2b
status: experimental
description: Detects NetScaler web service processes spawning shells or command utilities, consistent with web shell activity such as WHIPSHOT or SLAPSHOT on NetScaler ADC/Gateway appliances.
references:
  - https://securityaffairs.com/200046/security/whipshot-and-slapshot-the-tools-behind-an-active-citrix-netscaler-campaign.html
  - https://attack.mitre.org/techniques/T1505/003/
author: Security Arsenal
date: 2026/10/08
tags:
  - attack.persistence
  - attack.t1505.003
  - attack.execution
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|endswith:
      - '/httpd'
      - '/nshttpd'
      - '/nsppe'
      - '/nsnetsvc'
  selection_child:
    Image|endswith:
      - '/sh'
      - '/bash'
      - '/dash'
      - '/python'
      - '/python2'
      - '/python3'
      - '/perl'
      - '/php'
      - '/curl'
      - '/wget'
      - '/nc'
      - '/ncat'
      - '/socat'
      - '/base64'
      - '/chmod'
  condition: selection_parent and selection_child
falsepositives:
  - Rare legitimate NetScaler maintenance scripts executed during patching or firmware operations
level: critical
---
title: Suspicious File Written to NetScaler Web-Accessible Directory
id: 2b8c4d60-1f3a-4b5c-8d9e-0f1a2b3c4d5e
status: experimental
description: Detects creation or modification of script files in web-accessible NetScaler directories, a hallmark of web shell deployment (e.g., WHIPSHOT) on NetScaler ADC/Gateway.
references:
  - https://securityaffairs.com/200046/security/whipshot-and-slapshot-the-tools-behind-an-active-citrix-netscaler-campaign.html
  - https://attack.mitre.org/techniques/T1505/003/
author: Security Arsenal
date: 2026/10/08
tags:
  - attack.persistence
  - attack.t1505.003
  - attack.initial_access
  - attack.t1190
logsource:
  category: file_event
  product: linux
detection:
  selection_path:
    TargetFilename|contains:
      - '/netscaler/portal/'
      - '/netscaler/ns_gui/'
      - '/var/vpn/'
      - '/var/tmp/netscaler/'
      - '/var/netscaler/gui/'
  selection_ext:
    TargetFilename|endswith:
      - '.php'
      - '.pl'
      - '.cgi'
      - '.py'
      - '.sh'
  filter_legit:
    TargetFilename|contains:
      - '/netscaler/portal/templates/'
      - '/netscaler/portal/locale/'
  condition: selection_path and selection_ext and not filter_legit
falsepositives:
  - Custom portal customizations deployed by NetScaler administrators
  - Firmware update operations writing to GUI directories
level: high
---
title: Outbound Network Connection from NetScaler Appliance Process
id: 9e1d2c30-4a5b-6c7d-8e9f-0a1b2c3d4e5f
status: experimental
description: Detects uncommon outbound network connections initiated from NetScaler appliance processes, indicative of command-and-control or exfiltration following web shell deployment such as WHIPSHOT or SLAPSHOT.
references:
  - https://securityaffairs.com/200046/security/whipshot-and-slapshot-the-tools-behind-an-active-citrix-netscaler-campaign.html
  - https://attack.mitre.org/techniques/T1071/
  - https://attack.mitre.org/techniques/T1041/
author: Security Arsenal
date: 2026/10/08
tags:
  - attack.command_and_control
  - attack.t1071
  - attack.exfiltration
logsource:
  category: network_connection
  product: linux
detection:
  selection_proc:
    Image|endswith:
      - '/sh'
      - '/bash'
      - '/python'
      - '/perl'
      - '/curl'
      - '/wget'
      - '/nc'
      - '/ncat'
      - '/socat'
  filter_common_dest:
    DestinationPort:
      - 53
      - 123
      - 389
      - 636
      - 1812
      - 1813
  condition: selection_proc and not filter_common_dest
falsepositives:
  - Administrator-initiated troubleshooting (curl/wget to vendor endpoints) — tune against a change window
level: high

KQL — Microsoft Sentinel (Syslog/CEF Ingestion)

NetScaler supports syslog and CEF forwarding — if you are not already forwarding appliance logs to Sentinel, do it today. The first query hunts for process execution anomalies reported via syslog; the second hunts for HTTP requests to suspicious script paths in gateway access logs.

KQL — Microsoft Sentinel / Defender
// Hunt 1: Shell/utility execution observed in NetScaler syslog forwarding
Syslog
| where TimeGenerated > ago(14d)
| where Computer has_any ("netscaler", "ns", "adc", "gateway") // tune to your host naming
| where SyslogMessage has_any ("/bin/sh", "/bin/bash", "python", "perl", "curl ", "wget ", "nc ", "ncat", "socat", "base64 -d")
| where SyslogMessage has_any ("httpd", "nsppe", "nshttpd") or SeverityLevel in ("crit", "alert")
| project TimeGenerated, Computer, ProcessName, SyslogMessage
| order by TimeGenerated desc;

// Hunt 2: HTTP requests to web-accessible script paths consistent with web shell access
CommonSecurityLog
| where TimeGenerated > ago(14d)
| where DeviceVendor == "Citrix" or DeviceProduct has "NetScaler"
| where RequestURL has_any ("/netscaler/portal/", "/var/vpn/", "/vpn/", "/ns_gui/")
| where RequestURL endswith ".php" or RequestURL endswith ".cgi" or RequestURL endswith ".pl" or RequestURL endswith ".py"
| summarize RequestCount = count(), DistinctSources = dcount(SourceIP) by RequestURL, SourceIP, bin(TimeGenerated, 1h)
| where RequestCount < 50 // web shells typically see low-volume, targeted access
| order by TimeGenerated desc;

// Hunt 3: Outbound connections from NetScaler hosts to rare external destinations
CommonSecurityLog
| where TimeGenerated > ago(14d)
| where DeviceVendor == "Citrix" or DeviceProduct has "NetScaler"
| where isnotempty(DestinationIP) and ipv4_is_private(DestinationIP) == false
| summarize ConnCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated)
    by DestinationIP, DestinationPort, SourceHost = Computer
| join kind=leftanti (
    CommonSecurityLog
    | where TimeGenerated > ago(90d) and TimeGenerated < ago(14d)
    | summarize by DestinationIP
) on DestinationIP // keep only destinations NOT seen in the prior 90 days
| order by FirstSeen desc;

Velociraptor VQL — Appliance Filesystem and Process Hunting

If you have shell access to the appliance (or a forensic collection workflow), the following VQL artifacts hunt for recently created script files in web-accessible paths and anomalous processes. These are designed to run against collected images or via an agent on a Linux-based monitoring point with the NetScaler filesystem mounted.

VQL — Velociraptor
-- Hunt for recently created or modified script files in NetScaler web-accessible directories
SELECT FullPath, Size, Mtime, Atime, Ctime, Mode
FROM glob(globs=[
  '/netscaler/portal/**/*.php',
  '/netscaler/portal/**/*.cgi',
  '/netscaler/portal/**/*.pl',
  '/netscaler/ns_gui/**/*.php',
  '/var/vpn/**/*.php',
  '/var/vpn/**/*.cgi',
  '/var/tmp/netscaler/**'
])
WHERE Mtime > now() - 60*60*24*30  -- files modified in the last 30 days
ORDER BY Mtime DESC

-- Hunt for shell and utility processes that should not be running on a NetScaler appliance
SELECT Pid, Ppid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE Name =~ '(?i)^(bash|sh|dash|python.*|perl|php|nc|ncat|socat)$'
   OR CommandLine =~ '(?i)(base64 -d|/dev/tcp/|wget http|curl http|chmod \+x)'

-- Hunt for outbound network connections from non-standard processes
SELECT Pid, Name, Raddr, Rport, Status
FROM netstat()
WHERE Status =~ 'ESTABLISHED'
  AND NOT Raddr =~ '^(10\\.|172\\.(1[6-9]|2[0-9]|3[0-1])\\.|192\\.168\\.|127\\.)'
  AND Name !~ '(?i)^(nsconmsg|nsppe|nsaggreg|snmpd|ntpd)$'
ORDER BY Raddr

Remediation and Verification Script

Run the following from an SSH session on the appliance (root shell) to inventory suspicious artifacts, check persistence, and verify build/patch state. Review all output before taking destructive action — if you find a web shell, preserve it as evidence and engage your IR retainer before cleanup.

Bash / Shell
#!/bin/bash
# NetScaler compromise assessment - CVE-2026-88772 / WHIPSHOT / SLAPSHOT
# Run as root on the appliance shell. Review output; preserve evidence before remediation.

echo "=== [1] Current build / patch state ==="
show version 2>/dev/null || cat /etc/version 2>/dev/null

echo "=== [2] Recently modified files in web-accessible directories (last 30 days) ==="
find /netscaler/portal /netscaler/ns_gui /var/vpn /var/netscaler/gui -type f \
  \( -name "*.php" -o -name "*.cgi" -o -name "*.pl" -o -name "*.py" -o -name "*.sh" \) \
  -mtime -30 -ls 2>/dev/null

echo "=== [3] Suspicious files in /var/tmp/netscaler ==="
find /var/tmp/netscaler -type f -mtime -30 -ls 2>/dev/null

echo "=== [4] Files with mismatched timestamps (web shell timestomping check) ==="
# Compare against known-good baseline if available; flag newest files for manual review
ls -ltR /netscaler/portal/scripts 2>/dev/null | head -40

echo "=== [5] Persistence: cron and startup entries ==="
cat /etc/crontab 2>/dev/null
ls -la /var/cron/tabs/ 2>/dev/null
grep -r "" /nsconfig/rc.conf 2>/dev/null | head -20

echo "=== [6] Running shell/utility processes ==="
ps aux | grep -Ei 'bash|/bin/sh|python|perl|php|nc |ncat|socat' | grep -v grep

echo "=== [7] Established outbound connections (non-private destinations) ==="
netstat -an | grep ESTABLISHED | grep -Ev '127\.0\.0\.1|10\.|172\.(1[6-9]|2[0-9]|3[0-1])\.|192\.168\.'

echo "=== [8] Recent authentication anomalies in ns.log ==="
grep -iE 'login|auth' /var/log/ns.log 2>/dev/null | tail -100

echo "=== [9] Unrecognized files in nsconfig (config injection check) ==="
find /nsconfig -type f -mtime -30 -ls 2>/dev/null | grep -v -E 'ns.conf|ssl|license'

echo ""
echo "=== ASSESSMENT COMPLETE ==="
echo "If any web shell or unknown persistence is found: do NOT delete it."
echo "Isolate the appliance from the network, capture a forensic image, and engage IR."
echo "Credential rotation (LDAP bind, local nsroot, certificates/keys) is MANDATORY on any confirmed compromise."

Remediation

Immediate Actions (Within 24 Hours)

  1. Patch all NetScaler ADC and Gateway appliances to the fixed build identified in the Citrix security bulletin for CVE-2026-88772. Pull the exact fixed version numbers directly from the official advisory: Citrix Security Bulletins. Do not rely on secondary sources for build numbers — verify against the vendor bulletin.
  2. Hunt before you patch. Patching a compromised appliance does not remove web shells or persistence — WHIPSHOT and SLAPSHOT survive the patch. Run the assessment script above and review filesystem, process, and network telemetry before upgrading so evidence is not destroyed.
  3. Verify the management interface is not internet-exposed. The NSIP/management GUI must be reachable only from a dedicated management network. Confirm via external attack surface scanning.
  4. Forward logs now. Enable syslog/CEF forwarding from all appliances to your SIEM. Retain at least 90 days. If logs were not previously forwarded, assume you have a visibility gap covering the exploitation window.

If Compromise Is Confirmed or Suspected

Per Mandiant/GTIG guidance for NetScaler intrusions and our own IR experience with this exact scenario:

  • Treat the appliance as fully compromised at root. Rebuild from a known-good image rather than cleaning in place.
  • Rotate everything the appliance touched: the nsroot and all local admin accounts, LDAP/AD bind account credentials, RADIUS shared secrets, and any service accounts whose credentials traverse the gateway. Rotate certificates and private keys stored on the appliance.
  • Force global session and password resets for users who authenticated through the gateway during the exposure window. Assume credential theft occurred.
  • Review downstream authentication logs (AD, Entra ID, VPN, SaaS) for use of credentials that transited the compromised gateway.
  • Engage your IR retainer early. These actors are persistent; incomplete remediation of NetScaler intrusions is the single most common reason we get called back to the same client.

Hardening (Ongoing)

  • Enforce management-plane access via jump host + MFA; never expose the NSIP or GUI publicly.
  • Maintain a known-good file integrity baseline of web-accessible directories and alert on drift.
  • Subscribe to Citrix security bulletins and the CISA Known Exploited Vulnerabilities catalog; NetScaler CVEs with active exploitation are routinely added to KEV with short federal remediation deadlines — track the same SLA internally.
  • Include edge appliances in your penetration testing scope. Web shell persistence on NetScaler is one of the highest-value findings we deliver in assessments precisely because traditional EDR never sees it.

The Bottom Line

CVE-2026-88772 is a critical, actively exploited vulnerability with custom post-exploitation tooling already deployed against real victims. If you run NetScaler ADC or Gateway, your action items today are: hunt first, patch second, and assume compromise means credential rotation. Edge appliances are the front door — and right now, the lock is broken.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.