GreyNoise tracks massive Citrix Gateway recon using 63K+ residential proxies and AWS
ID: a60debe2-b611-5873-ab97-3a675781749f
STIX ID: report--a60debe2-b611-5873-ab97-3a675781749f
Feed Name: Security Affairs
GreyNoise observed a coordinated, large-scale reconnaissance campaign targeting Citrix ADC/NetScaler Gateways between Jan 28 and Feb 2, 2026: attackers used 63,000+ residential proxies to find login panels and then switched to AWS IPs to rapidly enumerate software versions across ~111,834 sessions. The activity displayed consistent TTPs (identical TCP option ordering, distinct browser fingerprints, VPN/tunnel routing, datacenter jumbo-frame usage), included IoCs, and is assessed as deliberate infrastructure mapping likely intended to support follow-on exploitation of Citrix instances.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
