Dual-Mode Citrix Gateway Reconnaissance: When Residential Proxies Meet Version Hunting
ID: 23108dcc-09eb-5a1a-98a5-6c378113dd77
STIX ID: report--23108dcc-09eb-5a1a-98a5-6c378113dd77
Feed Name: GreyNoise Labs
Threat Score
### Executive summary A coordinated reconnaissance campaign (111,834 sessions from 63,000+ source IPs) targeted Citrix ADC/Netscaler gateways between 2026-01-28 and 2026-02-02 to discover login panels and enumerate versions (notably accessing /epa/scripts/win/nsepa_setup.exe). The activity used residential proxy rotation and an AWS-hosted version disclosure sprint, showing operational sophistication and strong indicators of pre-attack infrastructure mapping.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
