Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances
Loading article
Security
Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances
Google Cloud Blog·3d ago·26 min read
By {"$":{"xmlns:author":"http://www.w3.org/2005/Atom"},"name":["Mandiant "],"title":[""],"department":[""],"company":[""]}
JavaScriptRedisInterviewNext.jsSecurity
AI summary
Mandiant and Google Threat Intelligence analysts identified active exploitation of zero-day vulnerabilities in Citrix NetScaler appliances that grant attackers root-level access. By exploiting heap memory corruption in the NSPPE packet engine, attackers deploy custom web shells and tunneling tools to facilitate internal network reconnaissance and credential theft.
Key points
Exploitation of CVE-2026-88772 bypasses authentication by triggering heap memory corruption in the NetScaler Packet Processing Engine.
Attackers leverage custom web shells like WHIPSHOT to hide Base64-encoded command-and-control payloads within HTTP headers.
The SLAPSHOT Python tunneler is used to proxy traffic into internal environments for lateral movement and reconnaissance.
Syslog monitoring for specific SSL handshake failures and NSPPE process terminations can serve as an indicator of compromise.