Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

Summary

Threat actors are actively exploiting a recently patched vulnerability in Citrix NetScaler ADC and NetScaler Gateway appliances. The attackers have gained root access to target organizations in North America and Europe across various sectors, including government, finance, and technology.

IFF Assessment

FOE

The exploitation of a critical vulnerability leading to root access and further deployment of malicious tools is detrimental to the security of targeted organizations.

Severity

9.0 Critical (AI Estimated)

The vulnerability allows attackers to gain root access to NetScaler appliances, which are critical infrastructure components, indicating a high impact. The observed exploitation suggests the vulnerability is likely easily discoverable and exploitable.

Defender Context

This highlights the critical importance of promptly patching NetScaler appliances, as active exploitation is already underway. Defenders should prioritize identifying and securing vulnerable systems, monitor for indicators of compromise related to WHIPSHOT and SLAPSHOT, and review access logs for unusual activity.

Read Full Story →