GreyNoise reported a coordinated, large-scale reconnaissance campaign targeting Citrix ADC Gateway / NetScaler Gateway infrastructure observed from Jan 28 to Feb 2, 2026, consistent with pre-exploitation mapping of exposed systems. The activity generated 111,834 scanning sessions from 63,000+ unique IPs, with ~79% of traffic aimed at Citrix Gateway honeypots—well above typical background scanning—indicating deliberate targeting rather than opportunistic crawling.
The operation used two complementary modes: (1) broad login panel discovery against /logon/LogonPoint/index.html driven largely by residential proxy rotation (with additional traffic attributed to Azure), and (2) a short, concentrated version-enumeration burst from 10 AWS-hosted IPs targeting /epa/scripts/win/nsepa_setup.exe (an EPA artifact) to infer product versions for exploit validation or version-specific exploit development. Researchers noted attacker tradecraft such as an older Chrome 50 user agent and the tight timing/coordination of the two scan types, aligning with patterns seen ahead of exploitation of known Citrix ADC weaknesses.

Map this exposure pattern across your cloud, code, and identities.
4 events from the most recent confirmed update back to the earliest known activity.
On February 3, 2026, GreyNoise's findings were publicly reported, attributing the activity to a dual-mode reconnaissance effort using residential proxies and AWS infrastructure. The report assessed the scanning as likely preparatory work for exploitation of known Citrix weaknesses and shared detection and hardening guidance.
GreyNoise observed the reconnaissance campaign through February 2, 2026, recording 111,834 sessions from more than 63,000 unique IP addresses, with 79% of activity aimed at Citrix Gateway honeypots. The pattern indicated deliberate infrastructure mapping rather than routine internet background scanning.
On February 1, 2026, the campaign included a short, intense AWS-hosted scanning burst focused on the Citrix Endpoint Analysis (EPA) setup file path to infer exposed product versions. The activity used uniform HTTP fingerprints and an outdated Chrome 50 user agent, suggesting automated tooling for pre-exploitation mapping.
A large-scale reconnaissance operation targeting Citrix ADC/NetScaler Gateway infrastructure began on January 28, 2026. Attackers used tens of thousands of residential proxy IPs, along with some cloud infrastructure, to identify exposed Citrix login panels at scale.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.