Back Theregister Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services
Two questions remain: who is abusing the CVEs? And why did Citrix take so long to disclose?
Certainties in life: Death, taxes, and critical Citrix vulns under attack 1 day ago
Certainties in life: Death, taxes, and critical Citrix vulns under attack
ShinyHunters tells The Reg: We hacked the FBI to 'protect our business' 3 days ago
ShinyHunters tells The Reg: We hacked the FBI to 'protect our business'
Someone's attacking a critical 0-day RCE in F5 BIG-IP APM 5 days ago
Someone's attacking a critical 0-day RCE in F5 BIG-IP APM
Researchers used Claude to hack OpenAI employees' ChatGPT accounts 11 days ago
Researchers used Claude to hack OpenAI employees' ChatGPT accounts
Google Pixel phones pwned in zero-click attacks 12 days ago
Google Pixel phones pwned in zero-click attacks
The public still doesn’t know who is abusing a critical Citrix vulnerability exploited as a zero-day weeks before disclosure, but we now know that the unknown digital intruders have used CVE-2026-88772 to break into government agencies, financial services firms, education organizations, and legal and professional services sectors across North America and Europe.
And everyone agrees that the vendor took way too long to disclose the security holes.
GreyNoise said it spotted an attempt to exploit CVE-2026-88771 against a Citrix NetScaler Gateway on September 24. Google researchers, meanwhile, said the CVE-2026-88772 campaign has been ongoing “since at least early September.”
“Why Citrix took so long to disclose these vulnerabilities is a question only Citrix can answer,” Benjamin Harris, founder and CEO of exposure management firm watchTowr, told The Register .
Citrix did not respond to our questions this.
“The vulnerabilities were discovered during incident response and forensic investigations at organizations already compromised, meaning both the exploitation and Citrix’s awareness of it predated public disclosure,” Harris said. “Citrix has a history of delaying the publication of vulnerabilities, even when they’re being exploited in the wild and affecting customers.”
So if you use Citrix NetScaler ADC and NetScaler Gateway appliances, and haven’t already applied the security updates, do that ASAP. But first, check your systems for signs of compromise, warns Mandiant Consulting CTO Charles Carmakal.
“Given the active exploitation, NetScaler customers should prioritize examining their systems for compromise *before* upgrading/patching,” Carmakal said on . “If you find evidence of web shells or other malicious files, please preserve evidence and investigate the scope of the compromise. Patching alone may not eradicate the threat actor from your environment.”
Citrix disclosed eight CVEs on Sunday with the worst of the bunch – CVE-2026-88771 and CVE-2026-88772 – earning critical 9.5 CVSS scores. “Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed,” the vendor said .
CVE-2026-88771 can allow an unauthenticated attacker to execute arbitrary commands remotely. CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service when DTLS is enabled, as it is by default on VPN virtual servers.
But by the time Citrix issued security advisories and warned customers the vulnerabilities, they were already under attack.
“No attribution has been made public, and we have yet to identify a clear trend among targets by industry or organization size,” Harris said. “Historically, NetScaler vulnerabilities have been exploited by both state- groups and ransomware operators.”
WatchTowr on Tuesday published a technical writeup CVE-2026-88772, plus a detection artifact generator for Citrix users to determine if they are vulnerable and to help with remediation.
Also on Tuesday, Google’s threat intel businesses provided additional details the exploitation campaign’s targets and the attacker’s custom malware.
“We have observed evidence that organizations in North America and Europe in the government, financial services, education, legal and professional services sectors were likely impacted by this exploitation campaign, which has been ongoing since at least early September,” Google Threat Intelligence Group and Mandiant said in an advisory .
After analyzing the intruder’s post-exploit toolkit, the malware hunters found never-before-seen malware used to establish persistent root access and proxy traffic into internal corporate networks.
The custom malware includes WHIPSHOT, a PHP web shell, and SLAPSHOT, a TCP tunneling tool written in Python.
WHIPSHOT is disguised as a Debian package and hides Base64-encoded command-and-control payloads in native HTTP headers. It functions as an HTTP transport bridge for SLAPSHOT, which accepts commands from WHIPSHOT and forwards arbitrary TCP streams to internal hosts.
Supported commands include:
open, which establishes an outbound TCP socket to a target host and port.
open, which establishes an outbound TCP socket to a target host and port.
push, which writes data to an open session.
push, which writes data to an open session.
pull, which polls and reads data from an open session socket.
pull, which polls and reads data from an open session socket.
exch, which sends and receives command-and-control data to and from an open session socket.
exch, which sends and receives command-and-control data to and from an open session socket.
close, which terminates a specified network session.
close, which terminates a specified network session.
ping, which performs a basic health-check verification.
ping, which performs a basic health-check verification.
“In at least one observed intrusion, the threat actor routed traffic through this proxy to manually conduct internal reconnaissance and credential theft,” the threat intel teams noted.
Google did not immediately respond to The Register ’s questions the campaign, including how many exploitation attempts and successful intrusions its threat hunters observed. Its advisory notes that the Citrix campaign “underscores the continued targeting of edge devices to gain initial access to victim networks, a trend that GTIG has tracked across a range of threat actors.”
Security and networking vulnerabilities accounted for half of enterprise-related zero-days in 2025 , according to Google’s count.
Attackers love edge devices - application delivery controllers, VPN gateways, and firewalls - because they provide direct access from the open internet to corporate networks, allowing attackers to bypass endpoint detection tools and other security layers.
NetScaler, in particular, is notoriously buggy. Attackers exploited another critical NetScaler vuln in March. A year earlier, Citrix disclosed multiple zero-days in the same product. ®
Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services
Two questions remain: who is abusing the CVEs? And why did Citrix take so long to disclose?
Open source tool distills Jev so you can run it locally
Jevstiller targets 98% agreement by learning familiar requests on your hardware while sending uncertain and audited queries upstream
Huawei Cloud Rolls Out Enterprise AI Products Across the Board, Building an Open Agentic Cloud
PARTNER CONTENT: Huawei Cloud strengthens the silicon bedrock on the cloud
Boeing's Calamity Capsule gets another shot at the ISS taxi business
Starliner-1 could fly by January, with astronauts to follow by 2028 if all goes well
Open source datacenters and open source thinking will undo self-inflicted DC damage
Denial and distraction have served the bit barn barons very badly. Wise up
Microsoft sends PDFs to strange new worlds instead of SharePoint
Use SharePoint Online? Keen on PDFs? Then you won't be keen on the latest Word bug
Astronomer watches Starlink satellites sinking to build a ‘planetary barometer’
Astronomer watches Starlink satellites sinking to build a ‘planetary barometer’
ShinyHunters claims FBI hack: 'This is NOT financially motivated'
ShinyHunters claims FBI hack: 'This is NOT financially motivated'
UPDAted Register reader hit with surprise bill after Microsoft portals disagreed
Register reader hit with surprise bill after Microsoft portals disagreed
EXCLUSIVE Microsoft tells nonprofits their deleted M365 data isn't coming back
Microsoft tells nonprofits their deleted M365 data isn't coming back
Security firm finds naming AI agents after Seinfeld characters helps bots join the team
Security firm finds naming AI agents after Seinfeld characters helps bots join the team
DoJ: Uncle Sam bought forensics software from same Russian operation supplying FSB
DoJ: Uncle Sam bought forensics software from same Russian operation supplying FSB
Schneider gives datacenter switchgear the software-defined treatment Equinix pilot promises faster deployment and over-the-air upgrades without downtime, provided the code behaves itself
Schneider gives datacenter switchgear the software-defined treatment
Equinix pilot promises faster deployment and over-the-air upgrades without downtime, provided the code behaves itself
Investors are pricing in a 32.6% AI productivity boost for software engineers Economists turn stock movements into an estimate of anticipated gains – while warning that markets can get carried away
Investors are pricing in a 32.6% AI productivity boost for software engineers
Economists turn stock movements into an estimate of anticipated gains – while warning that markets can get carried away
AMD bets $8.2B that worlds matter more than words in AI AI pioneer Fei-Fei Li just co-founded spatial AI research company World Labs in 2024. Now it's joining AMD
AMD bets $8.2B that worlds matter more than words in AI
AI pioneer Fei-Fei Li just co-founded spatial AI research company World Labs in 2024. Now it's joining AMD
AWS needs to embrace its place as the Depot of AI infrastructure What's wrong with being a great wholesaler?
AWS needs to embrace its place as the Depot of AI infrastructure
What's wrong with being a great wholesaler?
French dev aims to solve bots' blindness so they can understand GUIs Because sometimes escaping your sandbox requires clicking a button
French dev aims to solve bots' blindness so they can understand GUIs
Because sometimes escaping your sandbox requires clicking a button
Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Russians are posing as Signal support to launch phishing attacks
PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack
PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Black Hat and DEF CON
DEF CON Franklin project enlists hackers to harden critical infrastructure
Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
EQT buys majority in Swiss cybersecurity biz Acronis
Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career
Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight
On the plus side, infosec's a good bet for a long, stable career
KDE turns 30 and someone's brought an AI-native desktop proposal Akademy talk imagines Plasma assembling itself around a personal model of each user
KDE turns 30 and someone's brought an AI-native desktop proposal
Akademy talk imagines Plasma assembling itself around a personal model of each user
Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line Acquisition gives open source CSS framework 'a stable long-term '
Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line
Acquisition gives open source CSS framework 'a stable long-term '
Switzerland tests a FOSS escape route from Microsoft 365 Swiss Army sticks a knife in American cloud apps with its own FOSS push
Switzerland tests a FOSS escape route from Microsoft 365
Swiss Army sticks a knife in American cloud apps with its own FOSS push
Feel peak Windows was 7? You might like Kumander Linux Debian and Xfce – solid, sensible choices – with a pretty skin
Feel peak Windows was 7? You might like Kumander Linux
Debian and Xfce – solid, sensible choices – with a pretty skin
Canonical shuttering some of its legacy chat channels The Ubuntu Pastebin went in June, IRC gets demoted
Canonical shuttering some of its legacy chat channels
The Ubuntu Pastebin went in June, IRC gets demoted
Audacity audio-editing app no longer looks like it's from the early 2000s The FOSS tool for audio editing has a fresh coat of paint, and new features to boot
Audacity audio-editing app no longer looks like it's from the early 2000s
The FOSS tool for audio editing has a fresh coat of paint, and new features to boot
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
