INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
NetScaler Zero-Day Attacks Target Government and Finance Orgs Worldwide
| 2026-09-28 07:13 CRITICAL MEDIUM EXPLOITED VULNERABILITY
Executive Summary
AI-generated
Government, finance organizations were targeted in a weeks-long series of NetScaler zero-day attacks that began at least early September and continued through late September. The attackers are believed to be suspected state-sponsored threat actors, although no specific attribution has been confirmed by the sources. At least 100 victim organizations have been affected across North America and Europe, with those impacted including government agencies, financial services firms, educational institutions, legal practices, and professional services companies. Attackers exploited critical vulnerabilities in NetScaler ADC and Gateway instances to gain root access, plant web shells, and steal credentials using tools that enable internal reconnaissance, lateral movement, and credential theft; these exploits were likely carried out by a variety of threat actors in the near term.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-88772, CVE-2019-18935 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
e6•••••.sig
e6•••••.ico
ef3064••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
944062••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
ee3bd4••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
10f705••••••••••••••••••••••••••
18fb4e••••••••••••••••••••••••••
1dbfda••••••••••••••••••••••••••
0a4be0••••••••••••••••••••••••••
972f86••••••••••••••••••••••••••••••••••
fe619d••••••••••••••••••••••••••••••••••
e23046••••••••••••••••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
w3•••••.exe
45.138.•••.•••
206.82.•••.•••
65.98.•••.•••
2.59.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-88772CVE-2026-88772
CVE-2019-18935CVE-2019-18935
CVE-2026-88771CVE-2026-88771
Target & Sectors
BENELUX
BENELUX
DACH
DACH
EUROPE
EUROPE
NORTH_AMERICA
NORTH_AMERICA
educationeducation
financefinance
governmentgovernment
legallegal
technologytechnology
Incident Timeline
September 2026
Attackers worldwide exploited a NetScaler zero-day vulnerability to gain root access, targeting multiple sectors including government, financial services, technology, education, and legal and professional services.
Click on any entity below to view its context and source!
industry
Government
The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted government, financial services, technology, education, and legal and professional services sectors.
industry
Education
The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted government, financial services, technology, education, and legal and professional services sectors.
industry
Legal
The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted government, financial services, technology, education, and legal and professional services sectors.
industry
Technology
The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted government, financial services, technology, education, and legal and professional services sectors.
attribution
Mandiant Consulting
The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted government, financial services, technology, education, and legal and professional services sectors.
attribution
Google Threat Intelligence Group
The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted government, financial services, technology, education, and legal and professional services sectors.
September 24
Threat actors worldwide exploited a previously unknown vulnerability in NetScaler on September 24, several days before the flaw was publicly disclosed and patched.
September 27
Attackers worldwide exploited a zero-day vulnerability in NetScaler instances, exposing approximately 50,000 systems as of September 27.
Click on any entity below to view its context and source!
general_metric
50,000 exposed NetScaler instances
Palo Alto Networks
reported
that there had been roughly 50,000 potentially exposed NetScaler instances as of September 27.
September 28, 2026
Attackers worldwide exploited the CVE-2026-88771 vulnerability in NetScaler ADC and Gateway to gain root access, with GreyNoise detecting increased malicious activity starting around 8:30 a.m. EDT on September 28, 2026.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-88771
"
The development comes as GreyNoise said it began seeing additional malicious cyber activity linked to the exploitation of CVE-2026-88771 beginning September 28, 2026, around 8:30 a.m. EDT, followed by a significant surge that same day around 10:30 p.m. EDT.
organisation
GreyNoise
"
The development comes as GreyNoise said it began seeing additional malicious cyber activity linked to the exploitation of CVE-2026-88771 beginning September 28, 2026, around 8:30 a.m. EDT, followed by a significant surge that same day around 10:30 p.m. EDT.
organisation
NetScaler ADC
"
Data from Censys shows that there are 42,735 hosts and 323,527 web properties running NetScaler ADC or NetScaler Gateway as of September 28, 2026.
organisation
Censys
"
Data from Censys shows that there are 42,735 hosts and 323,527 web properties running NetScaler ADC or NetScaler Gateway as of September 28, 2026.
infrastructure
42,735 hosts
"
Data from Censys shows that there are 42,735 hosts and 323,527 web properties running NetScaler ADC or NetScaler Gateway as of September 28, 2026.
general_metric
323,527 web properties
"
Data from Censys shows that there are 42,735 hosts and 323,527 web properties running NetScaler ADC or NetScaler Gateway as of September 28, 2026.
2026/09/28
Threat actors exploited CVE-2026-88772 and CVE-2026-88771 vulnerabilities in unpatched Citrix NetScaler ADC and Gateway appliances to gain root access, deploy web shells, and conduct internal reconnaissance.
Click on any entity below to view its context and source!
infrastructure
13,549 hosts
"The United States accounts for 13,549 hosts (32%), followed by Germany at 5,678 (13%), then the Netherlands, United Kingdom, and Switzerland at roughly 4% each," Censys
said
.
organisation
SweetPotato
The first case involved exploiting the vulnerability to execute a reverse shell connecting to 206.82.6.22, attempting privilege escalation using Potato-family tools like SweetPotato, and installing a Godzilla-style memory-based web shell that operates within the w3wp.exe process without requiring separate ASPX files.
organisation
ASEC
The AhnLab SEcurity intelligence Center (ASEC) has identified two vulnerability attack cases that exploited a remote code execution vulnerability (CVE-2019-18935) targeting unpatched Telerik UI for ASP.NET AJAX servers.
infrastructure
Windows
Both attacks targeted Windows IIS servers, enabling attackers to maintain persistent access, collect system information, and identify additional targets for future campaigns.
organisation
WordPress
The second case deployed a Rust-based scanner tool that searches for exposed WordPress installation pages across target systems and reports findings via Telegram.
organisation
Telegram
The second case deployed a Rust-based scanner tool that searches for exposed WordPress installation pages across target systems and reports findings via Telegram.
organisation
Google
In at least one case observed by Google, the threat actor is said to have relayed traffic through this proxy to manually conduct internal reconnaissance and credential theft.
Google’s Mandiant and Threat Intelligence Group (GTIG) have published details on attacks exploiting the NetScaler zero-days that Citrix patched over the weekend.
organisation
TCP
SLAPSHOT, a TCP tunneling tool written in Python, functions as an internal network bridge that accepts commands from WHIPSHOT and forwards arbitrary TCP streams to internal hosts with the goal of facilitating internal reconnaissance, lateral movement, and credential harvesting.
organisation
WHIPSHOT
SLAPSHOT, a TCP tunneling tool written in Python, functions as an internal network bridge that accepts commands from WHIPSHOT and forwards arbitrary TCP streams to internal hosts with the goal of facilitating internal reconnaissance, lateral movement, and credential harvesting.
victims
100 victim organizations
Cybersecurity expert Kevin Beaumont reported being aware of more than 100 victim organizations as of Tuesday, noting that the attacks appear to be part of an
espionage campaign
.
organisation
CVE-2026
The vulnerabilities
are tracked as CVE-2026-88771 and CVE-2026-88772, and they affect NetScaler ADC and NetScaler Gateway instances.
In a post shared on LinkedIn, Charles Carmakal, chief technology officer at Mandiant Consulting,
said
the targeted intrusions have impacted dozens of organizations, warning of "broad and opportunistic exploitation of CVE-2026-88772 and CVE-2026-88771 by a variety of threat actors in the near term.
organisation
NetScaler ADC
The vulnerabilities
are tracked as CVE-2026-88771 and CVE-2026-88772, and they affect NetScaler ADC and NetScaler Gateway instances.
organisation
NetScaler Gateway
The vulnerabilities
are tracked as CVE-2026-88771 and CVE-2026-88772, and they affect NetScaler ADC and NetScaler Gateway instances.
Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe.
organisation
WatchTowr
Security firm WatchTowr, one of the first to confirm in-the-wild exploitation, has released technical details on both
CVE-2026-88772
and
CVE-2026-88771
.
organisation
Mandiant Consulting
In a post shared on LinkedIn, Charles Carmakal, chief technology officer at Mandiant Consulting,
said
the targeted intrusions have impacted dozens of organizations, warning of "broad and opportunistic exploitation of CVE-2026-88772 and CVE-2026-88771 by a variety of threat actors in the near term.
organisation
the NetScaler Packet Processing Engine
"
"Exploitation of
CVE-2026-88772
bypasses authentication and triggers an unhandled termination of the NetScaler Packet Processing Engine (NSPPE) to establish initial root-level access," the tech giant
said
.
organisation
NSPPE
"
"Exploitation of
CVE-2026-88772
bypasses authentication and triggers an unhandled termination of the NetScaler Packet Processing Engine (NSPPE) to establish initial root-level access," the tech giant
said
.
organisation
the Datagram Transport Layer Security
As
detailed
by watchTowr Labs, CVE-2026-88772 (CVSS score: 9.5) is a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling in the NSPPE component.
organisation
DTLS
As
detailed
by watchTowr Labs, CVE-2026-88772 (CVSS score: 9.5) is a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling in the NSPPE component.
organisation
Citrix NetScaler ADC
Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe.
organisation
NetScaler
Google’s Mandiant and Threat Intelligence Group (GTIG) have published details on attacks exploiting the NetScaler zero-days that Citrix patched over the weekend.
"
The attack chain then progresses to establishing persistent root-level execution for its web shells by leveraging the installer web shells to alter the permissions of "/bin/sh," and then initiate a full NetScaler appliance reboot.
organisation
PHP
Mandiant
found
previously unseen malware in the attacks, including a PHP web shell named WHIPSHOT and a Python-based tunneling tool named SLAPSHOT.
The attacks have been observed weaponizing the flaw to deploy a post-exploitation toolkit that includes previously unreported PHP web shells, like WHIPSHOT, that are capable of disguising Base64-encoded command-and-control (C2) payloads within native HTTP headers.
organisation
the Set User ID
“The [malicious cyber actor] attempted to set both the Set User ID (setuid) and Set Group ID (setgid) bits on /bin/sh to obtain a root shell and install a password-protected webshell that accepts communication by the cookie value sent by the adversary.
organisation
Set Group ID
“The [malicious cyber actor] attempted to set both the Set User ID (setuid) and Set Group ID (setgid) bits on /bin/sh to obtain a root shell and install a password-protected webshell that accepts communication by the cookie value sent by the adversary.
organisation
GreyNoise
This may be to avoid persisting their commands in web logs,” GreyNoise explained.
infrastructure
Linux
The configuration also maps incoming HTTP requests ending in ".ico" under "/vpn/media/" directly to a corresponding ".sig" file with the same base name inside "/var/netscaler/gui/vpn/scripts/linux/."
"For example, clients accessing /vpn/media/e6ee7c85.ico would be served by the dropped PHP web shell e6ee7c85.sig," Google said.
This configuration change made it possible for the adversary to stage web shells with deceptive file type extensions in "/netscaler/gui/vpn/scripts/linux," Google's cybersecurity division added.
organisation
Root Access
Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT.
organisation
GET
"In at least one case, web server access logs showed GET requests returning HTTP 404 responses, but exhibiting elevated processing durations and multi-kilobyte response sizes."
"In subsequent days, the actor attempted access to non-existent .sig files, which generated missing-file errors in httperror-vpn logs implying the files were not there.
organisation
Application Delivery Controllers
"These appliances—including Application Delivery Controllers, VPN gateways, and firewalls—remain attractive targets because they are exposed to the internet, sit outside the reach of endpoint detection and response (EDR) tools, and often store or process credentials that can be used to move deeper into the network.
organisation
EDR
"These appliances—including Application Delivery Controllers, VPN gateways, and firewalls—remain attractive targets because they are exposed to the internet, sit outside the reach of endpoint detection and response (EDR) tools, and often store or process credentials that can be used to move deeper into the network.
organisation
Microsoft
"Microsoft hosts 4,254 (10%) and Amazon 3,013 (7%), consistent with NetScaler VPX virtual appliances deployed in the public cloud.
organisation
Amazon
"Microsoft hosts 4,254 (10%) and Amazon 3,013 (7%), consistent with NetScaler VPX virtual appliances deployed in the public cloud.
organisation
NetScaler VPX
"Microsoft hosts 4,254 (10%) and Amazon 3,013 (7%), consistent with NetScaler VPX virtual appliances deployed in the public cloud.
2026/09/29
Attackers worldwide exploited a NetScaler zero-day vulnerability for root access, escalating from mass reconnaissance to full-scale exploitation across multiple independent actors and campaigns.
Click on any entity below to view its context and source!
tactic
Reconnaissance
"What started as mass reconnaissance yesterday has now evolved into full-on mass exploitation across a multitude of independent actors and campaigns," the GreyNose team told The Hacker News.
organisation
The Hacker News
"What started as mass reconnaissance yesterday has now evolved into full-on mass exploitation across a multitude of independent actors and campaigns," the GreyNose team told The Hacker News.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
Both attacks targeted Windows IIS servers, enabling attackers to maintain persistent access, collect system information, and identify additional targets for future campaigns.
Metrics
victims
100
Victim Organizations
Cybersecurity expert Kevin Beaumont reported being aware of more than 100 victim organizations as of Tuesday, noting that the attacks appear to be part of an
espionage campaign
.
Metrics
infrastructure
13,549
Hosts
"The United States accounts for 13,549 hosts (32%), followed by Germany at 5,678 (13%), then the Netherlands, United Kingdom, and Switzerland at roughly 4% each," Censys
said
.
Metrics
infrastructure
Linux
Affected Product
The configuration also maps incoming HTTP requests ending in ".ico" under "/vpn/media/" directly to a corresponding ".sig" file with the same base name inside "/var/netscaler/gui/vpn/scripts/linux/."
"For example, clients accessing /vpn/media/e6ee7c85.ico would be served by the dropped PHP web shell e6ee7c85.sig," Google said.
This configuration change made it possible for the adversary to stage web shells with deceptive file type extensions in "/netscaler/gui/vpn/scripts/linux," Google's cybersecurity division added.
Metrics
infrastructure
42,735
Hosts
"
Data from Censys shows that there are 42,735 hosts and 323,527 web properties running NetScaler ADC or NetScaler Gateway as of September 28, 2026.
Intelligence Sources
AlienVault OTX
2026-09-28
AlienVault OTX
2026-09-29
SecurityWeek
2026-09-30
The Hacker News
2026-09-30
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T08:20
Comprehensive Tactical Telemetry
Highly Correlated Entities
32x
organisation
Identified Entity
SweetPotato
entity
6x
industry
Targeted Sector
Government
sector
6x
tactic
Cyber Operation Type
Privilege Escalation
tactic
5x
target region
Target Country
United States
country
5x
timeline
Temporal Reference
September 24
date
5x
general metric
%
32
%
4x
attribution
Attributing Entity
Threat Intelligence Group
authority
3x
vulnerability
Exploited CVE
CVE-2019-18935
cve
2x
infrastructure
Affected Product
Windows
software
2x
tactic
MITRE ATT&CK Technique
T1505.003 - Web Shell
technique
2x
general metric
Cve-2026
88,772
cve-2026
2x
target region
Target Region
EUROPE
region
2x
infrastructure
Hosts
13,549
hosts
Contextual Telemetry
Context Block
7 METRICS
victims
Victim Organizations
100
victim organizations
general metric
Exposed Netscaler Instances
50,000
exposed netscaler instances
general metric
Score
10
score
general metric
Responses
404
responses
general metric
Web Properties
323,527
web properties
general metric
Microsoft
4,254
microsoft
general metric
Amazon
3,013
amazon
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.