Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hackers Actively Scanning Citrix NetScaler Infrastructure to Discover Login Panels

Between January 28 and February 2, 2026, a large-scale reconnaissance campaign targeting Citrix ADC Gateway and NetScaler Gateway infrastructure was detected by the GreyNoise Global Observation Grid.

Between January 28 and February 2, 2026, a large-scale reconnaissance campaign targeting Citrix ADC Gateway and NetScaler Gateway infrastructure was detected by the GreyNoise Global Observation Grid.

The operation involved residential proxy rotation for login panel discovery and concentrated AWS-hosted version disclosure scanning, generating over 111,834 sessions from more than 63,000 unique IP addresses.

The campaign demonstrated sophisticated infrastructure-mapping capabilities, achieving a 79% targeting rate against Citrix Gateway honeypots, indicating deliberate reconnaissance rather than opportunistic crawling.

Threat actors operated two complementary attack modes, suggesting coordinated preparation for exploitation activities targeting known Citrix vulnerabilities .

The operation was split into two distinct campaigns with different objectives. The login panel discovery mode generated 109,942 sessions from 63,189 source IPs across residential proxy networks and Azure infrastructure, targeting the /logon/LogonPoint/index.html endpoint.

Conversely, the version disclosure campaign produced 1,892 sessions from 10 AWS IP addresses concentrated in us-west-1 and us-west-2 regions, focusing on the /epa/scripts/win/nsepa_setup.exe file path.

Active Scans for Citrix NetScaler Login Panels

This dual approach mirrors tactics from previous Citrix exploitation campaigns where attackers mapped vulnerable instances before deploying exploits.

A single Microsoft Azure Canada IP address (52.139.3[.]76) generated 39,461 sessions, representing 36% of all login panel traffic, using the Prometheus blackbox-exporter user agent string.

The operation was split into two distinct campaigns with different objectives.
Kyle Mercer · Thehackingpost

The remaining traffic originated from residential ISP networks across various countries, with each IP conducting only one session. This technique employs unique browser fingerprints for each connection, enabling continuous cycling of both IP addresses and user agent strings.

The distributed nature complicates detection and mitigation compared to traditional scanning campaigns.

The version disclosure component executed a focused six-hour scanning sprint on February 1st, with 10 AWS IP addresses firing 1,892 requests targeting the Citrix Endpoint Analysis setup file.

The campaign peaked at 02:00 UTC with 362 sessions, starting at 00:00 UTC with 192 sessions, and concluding at 05:00 UTC with 283 sessions. All source IPs used an identical Chrome 50 user agent from 2016 and shared uniform HTTP fingerprint characteristics.

The specific targeting of version-specific files suggests interest in exploiting or validating vulnerabilities against known Citrix ADC and NetScaler Gateway weaknesses, including recent critical vulnerabilities such as CVE-2025-5777 .

TCP-layer analysis revealed distinct infrastructure separation across the three attack components. The Azure scanner displayed VPN/tunnel nested encapsulation, while the AWS version scanners showed jumbo frame MSS values requiring datacenter switching infrastructure.

Despite different infrastructure types, all fingerprints shared identical TCP option ordering, indicating common tooling or frameworks, suggesting a single threat actor or coordinated group.

Advertisement

Organizations should implement immediate detection and defensive measures, including monitoring for unauthorized blackbox-exporter user agents, alerting on external access to /epa/scripts/win/nsepa_setup.exe , and flagging rapid /logon/LogonPoint/ enumeration patterns.

Defensive recommendations include reviewing external Citrix Gateway exposure, implementing authentication requirements for the /epa/scripts/ directory, and configuring Citrix Gateways to suppress version disclosure in HTTP responses.

Version Disclosure Campaign (AWS Infrastructure):

44.251.121[.]190 13.57.253[.]3 50.18.232[.]85 52.36.139[.]223 54.201.20[.]56 54.153.0[.]164 54.176.178[.]13 18.237.26[.]188 54.219.42[.]163 18.246.164[.]162

Login Panel Discovery (Azure Infrastructure):

Organizations operating Citrix ADC Gateway or NetScaler Gateway infrastructure should review access logs for connections from these IP addresses and implement enhanced monitoring for similar reconnaissance patterns.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories