WHIPSHOT and SLAPSHOT post-exploitation toolkit on Citrix NetScaler appliances
Malware Activity
Summary
Hide ▲
Show ▼
A post-exploitation toolkit built around WHIPSHOT and SLAPSHOT is being used after Citrix NetScaler compromises, giving attackers covert C2, reconnaissance, and credential theft capability. The activity was observed in September 2026 after exploitation of CVE-2026-88772 on exposed appliances. WHIPSHOT hides Base64-encoded payloads inside HTTP headers, while SLAPSHOT tunnels traffic into internal networks. The tooling increases the chance of persistent access and follow-on movement across victim environments.
Related Happenings
ErrTraffic and Cruciferra ClickFix BYOVD malware activity
Malware Activity
H score72
First: 20.08.2026 20:23
Last: 20.08.2026 20:23
Sources 1
About this happening:
The ErrTraffic framework is now being used to deliver Cruciferra through ClickFix lures, adding a BYOVD escalation path that can terminate security processes....
ErrTraffic and Cruciferra ClickFix BYOVD malware activity
Malware ActivityAbout this happening: The ErrTraffic framework is now being used to deliver Cruciferra through ClickFix lures, adding a BYOVD escalation path that can terminate security processes....
GreyVibe custom malware activity with LegionRelay, PhantomRelay, and FallSpy
Malware Activity
H score41
First: 29.05.2026 01:24
Last: 29.05.2026 01:24
Sources 1
About this happening:
GREYVIBE is a Russian-speaking malware activity targeting Ukraine and Ukraine-related entities since at least August 2025. The group uses spear-phishing e-mails*...
GreyVibe custom malware activity with LegionRelay, PhantomRelay, and FallSpy
Malware ActivityAbout this happening: GREYVIBE is a Russian-speaking malware activity targeting Ukraine and Ukraine-related entities since at least August 2025. The group uses spear-phishing e-mails*...
Havoc Demon payload deployment and persistence operation
Malware Activity
H score22
First: 03.03.2026 19:15
Last: 03.03.2026 19:15
Sources 1
About this happening:
A fake IT support operation is deploying Havoc Demon payloads to preserve access across compromised endpoints and support likely data exfiltration or ransomware fo...
Havoc Demon payload deployment and persistence operation
Malware ActivityAbout this happening: A fake IT support operation is deploying Havoc Demon payloads to preserve access across compromised endpoints and support likely data exfiltration or ransomware fo...
Timeline
-
30.09.2026 11:24 2 articles · 4h ago
WHIPSHOT and SLAPSHOT post-exploitation toolkit on Citrix NetScaler appliances
Initial DisclosureAttackers first bypassed authentication with CVE-2026-88772 on Citrix NetScaler appliances and obtained root access. They then installed persistent web shells to stage WHIPSHOT and SLAPSHOT for follow-on control.
Show sources
- Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT — thehackernews.com — 30.09.2026 11:24
- Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT — thehackernews.com — 30.09.2026 11:24