WHIPSHOT

WHIPSHOTWHIPSHOT

Description

PHP web shell reported by Mandiant and Google Threat Intelligence Group in intrusions exploiting Citrix NetScaler ADC and Gateway zero-day CVE-2026-88772. Disguised as a Debian package under /netscaler/ns_gui/vpn/scripts/linux/, it extracts Base64-encoded data split across custom HTTP request headers and relays it over loopback to the SLAPSHOT tunneler; if SLAPSHOT is not running, WHIPSHOT unpacks its embedded payload and launches it in the background. Not attributed to a named threat actor at the time of reporting.
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.