In July of this year, a critical zero-day vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway was discovered. It was a vulnerability allowing unauthenticated remote code execution, which was identified as CVE-2023-3519.
Already at the beginning of August, researchers discovered at least 640 servers that had already been compromised by attackers to insert webshells; by mid-August, this figure had grown to around 2,000 servers.