SLAPSHOT

SLAPSHOTSLAPSHOT

Description

TCP tunneling tool written in Python, reported by Mandiant and Google Threat Intelligence Group in intrusions exploiting Citrix NetScaler ADC and Gateway zero-day CVE-2026-88772. Companion to the WHIPSHOT web shell, which embeds it, launches it in the background and relays operator traffic to it over loopback; SLAPSHOT then proxies arbitrary TCP streams from the compromised appliance to internal hosts for reconnaissance and credential theft, using a custom binary wire protocol. It records its port and lock in /tmp/.uxdport and /tmp/.uxdlock, closes idle sessions and terminates itself after a period of inactivity. Not attributed to a named threat actor at the time of reporting.
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.