Find notable cyber news and cases, enriched with sources, timelines, and signals.

WHIPSHOT and SLAPSHOT post-exploitation toolkit on Citrix NetScaler appliances

Malware Activity
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

A post-exploitation toolkit built around WHIPSHOT and SLAPSHOT is being used after Citrix NetScaler compromises, giving attackers covert C2, reconnaissance, and credential theft capability. The activity was observed in September 2026 after exploitation of CVE-2026-88772 on exposed appliances. WHIPSHOT hides Base64-encoded payloads inside HTTP headers, while SLAPSHOT tunnels traffic into internal networks. The tooling increases the chance of persistent access and follow-on movement across victim environments.

Related Happenings

ErrTraffic and Cruciferra ClickFix BYOVD malware activity

Malware Activity
H score72 First: 20.08.2026 20:23 Last: 20.08.2026 20:23 Sources 1

About this happening: The ErrTraffic framework is now being used to deliver Cruciferra through ClickFix lures, adding a BYOVD escalation path that can terminate security processes....

GreyVibe custom malware activity with LegionRelay, PhantomRelay, and FallSpy

Malware Activity
H score41 First: 29.05.2026 01:24 Last: 29.05.2026 01:24 Sources 1

About this happening: GREYVIBE is a Russian-speaking malware activity targeting Ukraine and Ukraine-related entities since at least August 2025. The group uses spear-phishing e-mails*...

Havoc Demon payload deployment and persistence operation

Malware Activity
H score22 First: 03.03.2026 19:15 Last: 03.03.2026 19:15 Sources 1

About this happening: A fake IT support operation is deploying Havoc Demon payloads to preserve access across compromised endpoints and support likely data exfiltration or ransomware fo...

Timeline

  1. 30.09.2026 11:24 2 articles · 4h ago

    WHIPSHOT and SLAPSHOT post-exploitation toolkit on Citrix NetScaler appliances

    Initial Disclosure

    Attackers first bypassed authentication with CVE-2026-88772 on Citrix NetScaler appliances and obtained root access. They then installed persistent web shells to stage WHIPSHOT and SLAPSHOT for follow-on control.

    Show sources