WHIPSHOT is a PHP web shell and tunneling frontend deployed on compromised Citrix NetScaler ADC and Gateway appliances. It has been associated with exploitation of CVE-2026-88771 and CVE-2026-88772, which provided unauthenticated remote code execution on exposed NetScaler systems. WHIPSHOT masquerades as a Debian package and receives Base64-encoded control data in HTTP request headers, allowing its operators to conceal command-and-control traffic within apparently ordinary web requests. It can check for, extract, and start an embedded Python component, then acts as an HTTP bridge to the SLAPSHOT TCP tunneling tool. Together, WHIPSHOT and SLAPSHOT enable operators to proxy traffic from a compromised edge appliance to internal hosts. The tooling was observed in intrusions affecting organizations in North America and Europe, including government, financial services, education, legal, and professional-services entities. Public attribution for the campaign has not been established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2026-88772 is one of two actively exploited Citrix NetScaler ADC and NetScaler Gateway vulnerabilities. Google reported attacks targeting this vulnerability that deployed the WHIPSHOT webshell and SLAPSHOT TCP tunneling tool. | Google highlighted attacks targeting CVE-2026-88772, which resulted in the deployment of the WHIPSHOT webshell and SLAPSHOT TCP tunneling tool.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
WHIPSHOT extracts Base64-encoded data from HTTP request headers and forwards it to SLAPSHOT; web-shell requests appear as ordinary CSS or image requests.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously undocumented PHP web shell used following exploitation of Citrix NetScaler CVE-2026-88772. It is disguised as a Debian package, proxies command traffic to SLAPSHOT, checks whether SLAPSHOT is running, and can extract and launch embedded Python payloads.
A previously unseen PHP web shell used following Citrix NetScaler exploitation to establish persistent root-level access. It is disguised as a Debian package, embeds Base64-encoded C2 payloads in HTTP headers, and acts as an HTTP transport bridge for the SLAPSHOT tunneling tool.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.