SLAPSHOT is a Python-based TCP tunneling tool deployed on compromised Citrix NetScaler ADC and NetScaler Gateway appliances. It bridges the appliance's FreeBSD-based operating environment to internal hosts, allowing attackers to proxy arbitrary TCP traffic into victim networks. SLAPSHOT listens on a local loopback port and accepts commands from WHIPSHOT, a PHP web shell that serves as its HTTP transport frontend. Its session-control functionality allows operators to open connections, send and receive data, exchange traffic, and close connections. Attackers have used the tunnel for manual internal reconnaissance, credential theft, and lateral movement.
SLAPSHOT was identified in a September 2026 intrusion campaign involving exploitation of CVE-2026-88772, a NetScaler DTLS memory-corruption vulnerability that enabled unauthenticated root-level code execution. WHIPSHOT can launch an embedded SLAPSHOT payload in the background, providing a path from the compromised edge appliance into the internal network. SLAPSHOT terminates after ten minutes without active sessions or commands and deletes its port and lock artifacts, reducing residual evidence. The associated campaign affected organizations in North America and Europe across government, financial services, technology, education, and legal and professional-services sectors. No named threat actor has been publicly attributed to the campaign.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attackers are abusing CVE-2026-88772 alongside CVE-2026-88771, an unauthenticated remote code execution vulnerability caused by improper input validation. Citrix assigned both flaws a CVSS score of 9.5 and confirmed active exploitation.
The attackers are abusing CVE-2026-88772, a critical memory-overflow flaw in Citrix NetScaler ADC and NetScaler Gateway appliances. It affects appliances with Datagram Transport Layer Security enabled, which is enabled by default on VPN virtual servers.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
It receives commands hidden in HTTP request headers, decodes them from Base64, and forwards them to SLAPSHOT over a local loopback connection.
SLAPSHOT is a Python TCP tunneler that receives commands from WHIPSHOT and forwards arbitrary TCP streams to internal hosts.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Python tunneling tool delivered in attacks exploiting the Citrix NetScaler vulnerability CVE-2026-88772.
A Python-based TCP tunneling tool that enables attackers to pivot from a compromised NetScaler appliance into the victim's internal network, supporting reconnaissance, lateral movement, and credential theft.
A Python-based tunnelling tool that enables attackers to pivot from a compromised NetScaler edge appliance into the internal environment, supporting reconnaissance, credential theft, and lateral movement.
Python tunneling malware that turns a compromised NetScaler appliance into a proxy for access to internal systems. It supports reconnaissance, connections to internal hosts, credential theft, and lateral movement. Operators reportedly used it for manual reconnaissance and credential theft in one intrusion. Reported artifacts include /tmp/.uxdport and /tmp/.uxdlock; a nohup-launched Python process associated with /tmp/.uxd* is another possible indicator.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.