Citrix NetScaler ADC and Gateway Appliances Targeted in Active Attacks
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
Threat actors are actively exploiting zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances to obtain root-level access. The attacks involve deploying custom PHP web shells, including WHIPSHOT, alongside a Python-based TCP tunneler known as SLAPSHOT. These malicious tools enable internal reconnaissance, credential theft, and lateral movement across compromised enterprise networks.
Investigation
Mandiant and Google Threat Intelligence Group traced the exploitation of CVE-2026-88772 and CVE-2026-88771 to early September 2026. Researchers discovered that attackers leverage malformed DTLS record headers to trigger heap memory corruption within the NSPPE process. Subsequent activity includes modifying httpd.conf to establish persistence and assigning the SUID bit to /bin/sh to enable privilege escalation.
Mitigation
Organizations should prioritize upgrading Citrix NetScaler appliances to patched versions (14.1-73.37+ or 13.1-64.23+). Where immediate patching is not feasible, defenders should disable DTLS when possible and enforce upstream IP allow-listing for UDP/443. Limiting outbound network connectivity, particularly SMTP traffic over TCP/25, can further reduce exposure and disrupt attacker communications.
Response
If compromise is suspected, security teams should immediately isolate affected NetScaler appliances and suspend HA synchronization to prevent the propagation of malicious configurations. Rotate all appliance secrets, including administrator credentials, SSH keys, and TLS certificates. Revoke active administrative, Gateway, and VPN sessions, and thoroughly investigate downstream infrastructure for evidence of lateral movement.
Attack Flow
We are still updating this part.
Detections
Nohup Usage (via cmdline)
Possible Defense Evasion by Use of Base64 Command (via cmdline)
Cron File Was Created (via file_event)
Hidden File Was Created On Linux Host (via file_event)
IOCs (SourceIP) to detect: Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances
IOCs (DestinationIP) to detect: Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances
Detect PHP Execution Configuration Exploitation [Webserver]
Simulation Execution
-
Attack Narrative & Commands: An adversary has gained initial access to a Linux-based web server and aims to establish a persistent web shell. By exploiting a misconfiguration in the web server (simulating a Citrix NetScaler vulnerability), the attacker modifies the configuration to treat
.debfiles as PHP scripts. This allows them to upload a malicious payload disguised as a Debian package, which the server will then execute as code, providing the attacker with a remote command execution (RCE) interface. -
Regression Test Script:
#!/bin/bash # Simulation script to trigger the "Detect PHP Execution Configuration Exploitation" rule. TARGET_CONF="/etc/apache2/mods-enabled/php.conf" # Ensure target exists for simulation purposes sudo mkdir -p /etc/apache2/mods-enabled/ sudo touch $TARGET_CONF echo "[+] Simulating configuration exploitation..." # Triggering the AddHandler detection pattern echo "AddHandler application/x-httpd-php .deb" | sudo tee -a $TARGET_CONF > /dev/null # Triggering the AliasMatch detection pattern echo "AliasMatch ^/vpn/media/(.+).ico$ /var/netscaler/gui/vpn/scripts/linux/$1.sig" | sudo tee -a $TARGET_CONF > /dev/null # Triggering the php_flag engine pattern echo "php_flag engine on" | sudo tee -a $TARGET_CONF > /dev/null echo "[+] Simulation complete. Check SIEM for alerts." -
Cleanup Commands:
#!/bin/bash # Cleanup script to remove simulated malicious configurations. TARGET_CONF="/etc/apache2/mods-enabled/php.conf" if [ -f "$TARGET_CONF" ]; then echo "[+] Cleaning up simulation files..." sudo rm "$TARGET_CONF" fi echo "[+] Cleanup complete."