Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services

← Back to the feed

Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services

The Register · 3 hours ago

Attackers used two critical, previously undisclosed vulnerabilities in Citrix NetScaler appliances to break into organisations in North America and Europe. The incidents affected government, financial services, education, legal and professional services organisations; the attackers have not been publicly identified. Security researchers and a threat intelligence firm say the campaign began before Citrix disclosed the vulnerabilities, prompting criticism of the delay.

Citrix assigned the flaws CVSS scores of 9.5 and warned that both had been exploited on unpatched systems. One can allow unauthenticated remote command execution; the other is a memory overflow that can enable remote code execution or denial of service when DTLS is enabled, which is the default on VPN virtual servers. Researchers found custom malware, including a PHP web shell called WHIPSHOT and a Python TCP tunnelling tool called SLAPSHOT, used to maintain access and route traffic into internal networks. Experts advise customers to check for compromise before patching, since installing updates alone may not remove an attacker already inside.

  • Attackers exploited two critical Citrix flaws before public disclosure.
  • Targets included organisations across several sectors in North America and Europe.
  • Check for compromise before patching; malware may persist after updates.

Cybersecurity Technology

Read the full article at the source →