{
  "id": 10759359,
  "title": "Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services",
  "url": "https://urgent.news/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-10759359",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-29T17:49:45.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-professional-services/5299867"
  },
  "original_language": "en",
  "account": "Hackers have been using a zero-day vulnerability in Citrix software to infiltrate government agencies, financial institutions, educational organizations, and legal/ professional service sectors across North America and Europe. Citrix's delay in disclosing the vulnerabilities has raised concerns, with experts questioning the vendor's response time.\n\nMandiant Consulting CTO Charles Carmakal advised NetScaler customers to inspect their systems for compromise before applying patches, as evidence of web shells or malicious files may be present. Citrix has since disclosed eight critical vulnerabilities, with CVE-2026-88771 and CVE-2026-88772 being the most severe.\n\nGoogle's Threat Intelligence Group and Mandiant reported that the exploitation campaign has been ongoing since early September, targeting organizations across various sectors. The attackers used custom malware, including WHIPSHOT, a PHP web shell, and SLAPSHOT, a TCP tunneling tool, to establish persistent root access and proxy traffic within corporate networks. This allowed them to conduct reconnaissance, steal credentials, and move laterally within victim networks.",
  "summary": "Two questions remain: who is abusing the CVEs? And why did Citrix take so long to disclose?",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services",
        "url": "https://urgent.news/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks",
        "published": "2026-09-29T17:49:45.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}