The NetScaler web shell answers a request for a missing icon, and CISA says hunt before you patch
Mandiant's analysis of two Citrix NetScaler zero-days describes root access won through a DTLS handshake on UDP 443, then an appliance reconfigured so that a request for a missing interface icon returns a PHP web shell inside a 404. The persistence it leaves behind survives the update, which is why CISA's alert asks organisations to look for compromise first.
