logo

Dual-Mode Citrix Gateway Reconnaissance: When Residential Proxies Meet Version Hunting

ID: 23108dcc-09eb-5a1a-98a5-6c378113dd77

STIX ID: report--23108dcc-09eb-5a1a-98a5-6c378113dd77

Feed Name: GreyNoise Labs

Threat Score
70/100

Date Published: 2026-02-02

Date Updated: 2026-04-27

Author: hrbrmstr & 🔮Orbie✨

...
...

### Executive summary A coordinated reconnaissance campaign (111,834 sessions from 63,000+ source IPs) targeted Citrix ADC/Netscaler gateways between 2026-01-28 and 2026-02-02 to discover login panels and enumerate versions (notably accessing /epa/scripts/win/nsepa_setup.exe). The activity used residential proxy rotation and an AWS-hosted version disclosure sprint, showing operational sophistication and strong indicators of pre-attack infrastructure mapping.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.