Hackers Actively Scanning Citrix NetScaler Infrastructure to Discover Login Panels
Between January 28 and February 2, 2026, a large-scale reconnaissance campaign targeting Citrix ADC Gateway and NetScaler Gateway infrastructure was detected by the GreyNoise Global Observation Grid.
Between January 28 and February 2, 2026, a large-scale reconnaissance campaign targeting Citrix ADC Gateway and NetScaler Gateway infrastructure was detected by the GreyNoise Global Observation Grid.
The operation involved residential proxy rotation for login panel discovery and concentrated AWS-hosted version disclosure scanning, generating over 111,834 sessions from more than 63,000 unique IP addresses.
The campaign demonstrated sophisticated infrastructure-mapping capabilities, achieving a 79% targeting rate against Citrix Gateway honeypots, indicating deliberate reconnaissance rather than opportunistic crawling.
Threat actors operated two complementary attack modes, suggesting coordinated preparation for exploitation activities targeting known Citrix vulnerabilities .
The operation was split into two distinct campaigns with different objectives. The login panel discovery mode generated 109,942 sessions from 63,189 source IPs across residential proxy networks and Azure infrastructure, targeting the /logon/LogonPoint/index.html endpoint.
Conversely, the version disclosure campaign produced 1,892 sessions from 10 AWS IP addresses concentrated in us-west-1 and us-west-2 regions, focusing on the /epa/scripts/win/nsepa_setup.exe file path.
Active Scans for Citrix NetScaler Login Panels
This dual approach mirrors tactics from previous Citrix exploitation campaigns where attackers mapped vulnerable instances before deploying exploits.
A single Microsoft Azure Canada IP address (52.139.3[.]76) generated 39,461 sessions, representing 36% of all login panel traffic, using the Prometheus blackbox-exporter user agent string.
The operation was split into two distinct campaigns with different objectives.
The remaining traffic originated from residential ISP networks across various countries, with each IP conducting only one session. This technique employs unique browser fingerprints for each connection, enabling continuous cycling of both IP addresses and user agent strings.
The distributed nature complicates detection and mitigation compared to traditional scanning campaigns.
The version disclosure component executed a focused six-hour scanning sprint on February 1st, with 10 AWS IP addresses firing 1,892 requests targeting the Citrix Endpoint Analysis setup file.
The campaign peaked at 02:00 UTC with 362 sessions, starting at 00:00 UTC with 192 sessions, and concluding at 05:00 UTC with 283 sessions. All source IPs used an identical Chrome 50 user agent from 2016 and shared uniform HTTP fingerprint characteristics.
The specific targeting of version-specific files suggests interest in exploiting or validating vulnerabilities against known Citrix ADC and NetScaler Gateway weaknesses, including recent critical vulnerabilities such as CVE-2025-5777 .
TCP-layer analysis revealed distinct infrastructure separation across the three attack components. The Azure scanner displayed VPN/tunnel nested encapsulation, while the AWS version scanners showed jumbo frame MSS values requiring datacenter switching infrastructure.
Despite different infrastructure types, all fingerprints shared identical TCP option ordering, indicating common tooling or frameworks, suggesting a single threat actor or coordinated group.
Organizations should implement immediate detection and defensive measures, including monitoring for unauthorized blackbox-exporter user agents, alerting on external access to /epa/scripts/win/nsepa_setup.exe , and flagging rapid /logon/LogonPoint/ enumeration patterns.
Defensive recommendations include reviewing external Citrix Gateway exposure, implementing authentication requirements for the /epa/scripts/ directory, and configuring Citrix Gateways to suppress version disclosure in HTTP responses.
Version Disclosure Campaign (AWS Infrastructure):
44.251.121[.]190 13.57.253[.]3 50.18.232[.]85 52.36.139[.]223 54.201.20[.]56 54.153.0[.]164 54.176.178[.]13 18.237.26[.]188 54.219.42[.]163 18.246.164[.]162
Login Panel Discovery (Azure Infrastructure):
Organizations operating Citrix ADC Gateway or NetScaler Gateway infrastructure should review access logs for connections from these IP addresses and implement enhanced monitoring for similar reconnaissance patterns.
Based on reporting by Cyber Security News.
