logo

Wave of Citrix NetScaler scans use thousands of residential proxies

ID: 2413d2b6-8715-5619-8d9d-c7d4c25193d9

STIX ID: report--2413d2b6-8715-5619-8d9d-c7d4c25193d9

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-02-03

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A coordinated reconnaissance campaign (Jan 28–Feb 2) used over 63,000 residential-proxy IPs to launch ~111,834 sessions against Citrix NetScaler/ADC, focusing on authentication interfaces (/logon/LogonPoint/index.html) and EPA artifacts (/epa/scripts/win/nsepa_setup.exe) to enumerate versions and identify exposed gateways. GreyNoise characterizes the activity as organized pre-exploitation infrastructure mapping, highlights detection opportunities (user agent, HEAD requests, EPA path access, residential ISP sources), and notes relevance to recent high-severity Citrix CVEs such as CVE-2025-5777 and CVE-2025-5775.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.