Wave of Citrix NetScaler scans use thousands of residential proxies
ID: 2413d2b6-8715-5619-8d9d-c7d4c25193d9
STIX ID: report--2413d2b6-8715-5619-8d9d-c7d4c25193d9
Feed Name: Bleeping Computer
A coordinated reconnaissance campaign (Jan 28–Feb 2) used over 63,000 residential-proxy IPs to launch ~111,834 sessions against Citrix NetScaler/ADC, focusing on authentication interfaces (/logon/LogonPoint/index.html) and EPA artifacts (/epa/scripts/win/nsepa_setup.exe) to enumerate versions and identify exposed gateways. GreyNoise characterizes the activity as organized pre-exploitation infrastructure mapping, highlights detection opportunities (user agent, HEAD requests, EPA path access, residential ISP sources), and notes relevance to recent high-severity Citrix CVEs such as CVE-2025-5777 and CVE-2025-5775.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
