WHIPSHOT is a PHP web shell deployed on compromised Citrix NetScaler ADC and NetScaler Gateway appliances. Identified in September 2026, it was used in intrusions exploiting CVE-2026-88772, a pre-authentication DTLS memory-corruption vulnerability that enables root-level code execution on the appliances' underlying FreeBSD operating system. The associated campaign affected organizations in North America and Europe across government, financial services, technology, education, legal, and professional-services sectors. No public attribution to a named threat actor has been established.
WHIPSHOT masquerades as a Debian package or signature resource, with malicious web-server configuration changes enabling these resources to execute as PHP. It extracts Base64-encoded commands and payloads distributed across HTTP request headers and relays commands and results. It also serves as an HTTP transport frontend for SLAPSHOT, a Python TCP tunneling tool, forwarding decoded traffic over a local loopback connection. Together, the tools provide a bridge from the compromised appliance into internal networks; operators have used this access for reconnaissance, lateral movement, and credential theft. WHIPSHOT conceals its activity by blending command traffic into ordinary HTTP headers and returning misleading HTTP 404 responses. Its deployment provides persistent access that appliance vulnerability patching alone does not necessarily remove.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attackers are abusing CVE-2026-88772 alongside CVE-2026-88771, an unauthenticated remote code execution vulnerability caused by improper input validation. Citrix assigned both flaws a CVSS score of 9.5 and confirmed active exploitation.
The attackers are abusing CVE-2026-88772, a critical memory-overflow flaw in Citrix NetScaler ADC and NetScaler Gateway appliances. It affects appliances with Datagram Transport Layer Security enabled, which is enabled by default on VPN virtual servers.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
WHIPSHOT, built to hide Base64-encoded command-and-control instructions inside ordinary HTTP headers.
The lightweight PHP web shells were disguised as .deb and .sig files, while the hidden configuration hook made their execution appear as image requests for .ico files.
“The lightweight PHP web shells, which are dressed up as .deb and .sig files...”
It receives commands hidden in HTTP request headers, decodes them from Base64, and forwards them to SLAPSHOT over a local loopback connection.
WHIPSHOT acts as an HTTP proxy for SLAPSHOT, extracting Base64-encoded data from HTTP request headers and forwarding it to tunneling malware running on the compromised device.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A PHP web shell delivered in attacks exploiting the Citrix NetScaler vulnerability CVE-2026-88772.
A PHP web shell deployed on compromised NetScaler appliances. Disguised as a .deb file, it receives Base64-encoded commands in HTTP headers, relays them to SLAPSHOT through loopback, and uses fake 404 responses to conceal activity.
A PHP-based web shell that provides persistent access to compromised NetScaler appliances after exploitation.
PHP web shell deployed on compromised Citrix NetScaler appliances. It relays commands and results through HTTP headers containing Base64-encoded data and returns fake HTTP 404 responses to conceal activity. The report identifies HTTP_X_UX and HTTP_X_UX_[0-9]+ as WHIPSHOT command-and-control headers. Attackers modify Apache configuration to execute disguised PHP files and expose hidden web shells through apparently harmless icon-file requests.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.