Citrix zero-day custom malware attacks are targeting government agencies, banks and professional services firms, according to reporting from The Register. Two big questions remain unanswered: who is abusing the vulnerabilities, and why Citrix took so long to disclose them. For anyone who relies on remote access to get work done, the story is a useful reminder of how much trust sits in a single gateway appliance.

What we know about the Citrix zero-day custom malware attacks

The attacks center on Citrix NetScaler ADC and NetScaler Gateway products. Based on public reporting gathered around the story, Mandiant Consulting and Google Threat Intelligence Group identified active, in-the-wild exploitation in late September 2026. CISA then amplified Citrix's disclosure of eight new vulnerabilities affecting the two product lines.

Researchers at Aviatrix tie two of the flaws, CVE-2026-88771 and CVE-2026-88772, to the deployment of malware they call WHIPSHOT and SLAPSHOT. GreyNoise reported that on 24 September 2026 a malicious actor used a single IP address to attempt zero-day exploitation against a NetScaler Gateway. Dark Reading describes the bugs as critical and says they affect default configurations, which means organizations may be exposed without having made any risky setting changes.

The Register's headline points to the use of custom malware, which is worth pausing on. Purpose-built tooling suggests an attacker who planned for persistence and quiet access, not a quick smash-and-grab. The targeting of government, banks and professional services fits that picture, since those sectors hold sensitive data and often connect to many other organizations.

What we do not know is just as important. No public attribution has been established in the material we reviewed, so anyone naming a specific group should be treated with caution.

The disclosure delay and why it matters

The second open question is timing. The Register asks why Citrix took so long to disclose. We do not have a confirmed answer, and this article will not guess at one. But the reason the question matters is clear.

A zero-day is dangerous because defenders have no patch. Every day between first exploitation and public disclosure is a day when attackers can operate while customers have no reason to look for signs of compromise. Once a vendor discloses and a fix exists, defenders face a different problem: they must patch quickly and also work out whether they were breached before the patch landed. Patching closes the door but does not evict anyone already inside.

That is why researchers publishing indicators of compromise matters as much as the patch itself. If custom malware was planted before disclosure, updating the appliance alone may not be enough.

Why remote-access gateways keep getting targeted

Gateways and VPN-style appliances sit at the network edge, are reachable from the internet by design, and often have broad access to internal systems. That makes them attractive: one successful exploit can deliver a foothold that bypasses many internal controls. They also tend to run specialized software that is harder to monitor than a standard laptop or server.

We have seen this pattern before. The SonicWall SMA zero-days were another case of remote-access appliances exploited before defenders knew to look. The common thread is that attackers go where the access is concentrated.

The tooling side matters too. Attackers are increasingly able to buy evasion capabilities, as shown by the market for EDR evasion sold as a subscription. Custom malware on an edge device, where endpoint security tools often cannot run at all, compounds that advantage.

What This Means For You

If you are a security or IT professional at an organization running NetScaler, treat this as urgent. Confirm whether your appliances are affected, apply the vendor's fixes, and review the indicators of compromise published by researchers. Assume that patching alone does not prove you are clean.

If you are a remote worker, you cannot patch your employer's gateway, but you can still act. Report unexpected login prompts, forced password resets or unusual access behavior to your IT team quickly. Use multi-factor authentication wherever it is offered, and keep your own devices updated so they are not an easy second route in.

If you use a personal VPN, note that this story concerns enterprise gateway products, not consumer VPN services. The broader lesson still applies: any internet-facing access point is only as safe as its last update.

What organizations and remote workers can do now

  • Inventory your edge devices. You cannot patch what you do not know you have. List every internet-facing gateway and appliance.
  • Patch fast, then investigate. Apply fixes for the disclosed NetScaler vulnerabilities, then hunt for signs of earlier compromise using published indicators.
  • Limit exposure. Restrict management interfaces from the public internet and segment what a gateway can reach internally.
  • Monitor the edge. Send appliance logs to a central system and watch for unusual sessions or configuration changes.
  • Prepare for the next one. Have a plan for emergency patching outside normal maintenance windows.

Takeaway

The Citrix zero-day custom malware attacks show that remote-access gateways remain a prime target, and that the period before disclosure is when defenders are most blind. Who is behind the campaign and why disclosure took so long are still open questions, but the defensive steps do not depend on the answers. Take a fresh look at how your organization secures remote access and patches edge devices, and read our coverage of the SonicWall SMA zero-days as a parallel case of remote-access appliances exploited before disclosure.