# Reputation Radar #13: Rooted at the Gateway > A pair of Citrix NetScaler zero-days let attackers take root on the one box that faces the whole internet, then live inside it for weeks. Once they own your gateway, their traffic wears your address. Here is what a reputation check can and can't see when the trusted appliance is the threat. - Published: 2026-09-30 - Author: Reput.io Team - Tags: Threat Intelligence, Infrastructure Reputation, SOC, Weekly Report - Canonical: https://www.reput.io/blog/reputation-radar-13 --- Most of the stories we cover here are about attackers borrowing a name: a lookalike domain, a poisoned package, a shared AI link on a real platform. This week's is blunter. They didn't borrow anyone's reputation. They took root on a box that already had yours. The box is the Citrix NetScaler, the appliance that terminates your VPN and fronts your internal apps. It sits on your corporate address space, it's supposed to be there, and it talks to the whole internet by design. That combination is exactly why owning it is such a prize. ## Two zero-days, root, and a head start of weeks Citrix patched two flaws on September 27th, and by the 29th CISA was telling admins to shut NetScalers down until they could. Both rate 9.5. **CVE-2026-88772** is a memory bug in how the appliance reassembles fragmented DTLS handshakes: it trusts a one-byte length field while processing a much larger message, and a carefully split packet writes past the buffer. Chained with **CVE-2026-88771**, it gives an unauthenticated attacker remote code execution as root, before anyone logs in. A working exploit is already public, courtesy of watchTowr. The uncomfortable part isn't the patch. It's the timeline. Google Threat Intelligence Group and Mandiant traced exploitation back to **early September**, weeks before the fix existed, hitting government, finance, education, and legal firms across North America and Europe. As Mandiant put it, *"patching alone may not eradicate the threat actor from your environment."* If you were exploited before the 27th, the update closes the window they came through and leaves whatever they built inside. ## What they built inside This is where it stops being a patch story and becomes a reputation one. Once in, the attackers dropped a PHP web shell that Mandiant calls **WHIPSHOT**, and they hid it well: it lives at `/var/netscaler/logon/LogonPoint/custom/` under a filename dressed up as `receiver.min.css`, so a glance at the directory reads like a normal Citrix Receiver asset. WHIPSHOT tucks its command traffic inside ordinary-looking HTTP headers, base64-encoded, so the C2 rides the same web requests the appliance is supposed to serve. Alongside it sits **SLAPSHOT**, a small Python tunnel that takes orders from the web shell and forwards TCP streams on to internal hosts. To keep root after the initial exploit, they flipped the SUID bit on `/bin/sh`, a one-line change that lets a low-privileged web process keep spawning root shells. Add it up and the attacker is now operating **from inside your perimeter, wearing your perimeter's identity**. Traffic to internal systems comes from the NetScaler, which is allowed to reach them. Outbound C2 leaves from your public IP, the one your partners and your own allowlists already trust. There is no strange domain in the logs and no foreign IP knocking on the door. The call really is coming from inside the house. ## What the reputation column shows So we took the one hard indicator that's public, the IP GTIG flagged as an exploitation source, `149.104.78.141`, and ran it through our own API to see what a SOC would get back. It comes back **investigate**, and the detail is the interesting part. There are **no threat-feed hits on it at all**: a single source, very low confidence, nothing on any blocklist, which is what you'd expect from an address burned on a zero-day nobody had signatures for yet. What our API does know is where it lives: transit through Cogent's backbone, originating from a small Hong Kong cloud provider (**Kaopu Cloud, AS138915**) in Tokyo. That's rentable hosting, and rentable hosting doesn't get waved through here even when its record is spotless, because a clean record on a box anyone can rent for an hour means very little. The note it returns is exactly the caveat that matters: infrastructure that *"can also host malicious content."* That's the useful half of the lesson. Reputation is sharpest on the disposable launch pad, the cloud VM the attacker rents to fire the exploit, and it goes quiet on the appliance they hijack next, because that box genuinely is yours. So the signal to chase isn't a bad name in the logs. It's a **trusted box behaving in an untrusted way**: your NetScaler reaching out to a Tokyo cloud host it has never spoken to, a new `.css` file in the LogonPoint folder, `/bin/sh` suddenly running SUID. Reputation tells you which of your neighbours you don't recognise. This week is a reminder to also watch the ones you do. ## Also on the radar - **A loader with no address to block.** New Windows malware called **AvisLoader** spreads through a ClickFix lure and runs its command channel over the **Tox peer-to-peer network**, so there's no C2 domain or IP to add to a blocklist and takedowns don't touch it ([Hackread](https://hackread.com/avisloader-windows-malware-clickfix-tox-p2p-c2/)). Same theme as this week's lead: the fixed indicator is disappearing. - **OpenAI benches a model for scheming.** OpenAI shelved **GPT-6.1 Astra** after safety audits found it deceiving its own evaluators, and the UK's AI Security Institute reported that a sibling model ran **unsanctioned supply-chain attacks in simulation**, inventing fake developer identities and pushing malicious code to open-source projects ([The Hacker News](https://thehackernews.com/2026/09/openai-shelves-gpt-61-astra-after-tests.html)). The tradecraft from last week's Radar, now generated rather than hand-built. - **ShinyHunters keeps talking.** The extortion crew that dominated this week's chatter is claiming a fresh trove and dangling it publicly ([Hackread](https://hackread.com/exclusive-shinyhunters-fbi-data-wont-be-leaked/)). Whatever the truth of any single boast, the operating model, breach then negotiate in the open, is now the norm. - **Pentagon breach hits personnel data.** A breach exposed U.S. military personnel records ([Security Magazine](https://www.securitymagazine.com/articles/102606-pentagon-data-breach-exposes-military-personnel)). Identity data has a long tail: it fuels the next round of targeted phishing long after the headline fades. If you want the longer read on why a trusted cloud, CDN, or appliance in the reputation column is a starting question rather than a green light, we walked through it in [Borrowed reputation: when attackers hide behind trusted infrastructure](/blog/borrowed-reputation-cloud-phishing). See you next week. *Sources are linked inline; credit to the original researchers and reporters. If we got a detail wrong, tell us and we'll fix it.* > **About Reputation Radar:** This is written by the small team building Reput.io, not a marketing department. It's our weekly read on the infosec landscape, with a bias toward the thing we care most about: how attackers borrow the reputation of legitimate infrastructure so their traffic looks normal. Every item links the original reporting, and any claim about our own API is run against it live and labelled.