Urgent.News

What's breaking now, across thousands of outlets.

Tech

Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services

Two questions remain: who is abusing the CVEs? And why did Citrix take so long to disclose?

Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services

Hackers have been using a zero-day vulnerability in Citrix software to infiltrate government agencies, financial institutions, educational organizations, and legal/ professional service sectors across North America and Europe. Citrix's delay in disclosing the vulnerabilities has raised concerns, with experts questioning the vendor's response time.

Mandiant Consulting CTO Charles Carmakal advised NetScaler customers to inspect their systems for compromise before applying patches, as evidence of web shells or malicious files may be present. Citrix has since disclosed eight critical vulnerabilities, with CVE-2026-88771 and CVE-2026-88772 being the most severe.

Google's Threat Intelligence Group and Mandiant reported that the exploitation campaign has been ongoing since early September, targeting organizations across various sectors. The attackers used custom malware, including WHIPSHOT, a PHP web shell, and SLAPSHOT, a TCP tunneling tool, to establish persistent root access and proxy traffic within corporate networks. This allowed them to conduct reconnaissance, steal credentials, and move laterally within victim networks.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

Petrol, Diesel Get Cheaper Again

The federal government has decided to decrease the prices of motor spirit (MS) petrol and high-speed diesel (HSD) for the … Read More The post Petrol, Diesel Get Cheaper Again appeared first on…

More from Tuesday 29 September →