SLAPSHOT is a Python-based TCP tunneling and proxy tool deployed on compromised Citrix NetScaler ADC and Gateway appliances. It operates alongside the WHIPSHOT PHP web shell, which relays attacker commands to the local SLAPSHOT daemon through HTTP-based transport. SLAPSHOT enables an operator to open, manage, exchange data over, and close arbitrary TCP connections to internal hosts reachable from the compromised appliance, effectively using the appliance as a pivot into the victim network. It has been associated with exploitation of CVE-2026-88771 and CVE-2026-88772 affecting internet-facing NetScaler deployments. In observed intrusions, its proxy capability supported manual internal reconnaissance and credential theft. SLAPSHOT can terminate after inactivity, reducing its forensic footprint. The activity affected organizations in North America and Europe, including government, financial services, education, legal, and professional-services organizations; no public attribution has been established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2026-88772 is one of two actively exploited Citrix NetScaler ADC and NetScaler Gateway vulnerabilities. Google reported attacks targeting this vulnerability that deployed the WHIPSHOT webshell and SLAPSHOT TCP tunneling tool. | Google highlighted attacks targeting CVE-2026-88772, which resulted in the deployment of the WHIPSHOT webshell and SLAPSHOT TCP tunneling tool.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
WHIPSHOT extracts Base64-encoded data from HTTP request headers and forwards it to SLAPSHOT; web-shell requests appear as ordinary CSS or image requests.
WHIPSHOT acts as an HTTP proxy for SLAPSHOT, extracting Base64-encoded data from HTTP request headers and forwarding it to tunneling malware running on the compromised device.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously undocumented Python TCP tunneling malware controlled through WHIPSHOT. It bridges a compromised NetScaler appliance to internal systems, opens and manages connections to internal hosts, transfers data, supports reconnaissance and credential theft, and can self-terminate after inactivity.
A previously unseen Python TCP tunneling and proxy tool controlled through WHIPSHOT. It forwards arbitrary TCP streams to internal hosts and supports opening, writing to, polling, exchanging data with, closing, and health-checking TCP sessions. It was used to proxy traffic for internal reconnaissance and credential theft in at least one intrusion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.