GreyNoise tracks massive Citrix Gateway recon using 63K+ residential proxies and AWS

3 Min Read

GreyNoise spotted a dual-mode Citrix Gateway recon campaign using 63K+ residential proxies and AWS to find login panels and enumerate versions.

Between Jan 28 and Feb 2, 2026, GreyNoise tracked a coordinated reconnaissance campaign targeting Citrix ADC and NetScaler Gateways. Attackers used over 63,000 residential proxies to discover login panels, then switched to AWS infrastructure to aggressively enumerate exposed versions across more than 111,000 sessions.

- Advertisement -

The activity logged 111,834 sessions from over 63,000 IPs, with 79% aimed at Citrix Gateway honeypots, pointing to targeted infrastructure mapping rather than random crawling.

“The numbers tell the story: 111,834 sessions, 63,000+ unique source IPs, and a 79% targeting rate against Citrix Gateway honeypots specifically.” reads the report published by GreyNoise. “That last number matters—it’s well above baseline scanning noise, indicating deliberate infrastructure mapping rather than opportunistic crawling.”


What do you think? Post a comment.


Two related campaigns targeted Citrix infrastructure just before February 1, 2026. One scanned the web to find login panels, while the other quickly checked software versions, showing a coordinated reconnaissance effort.

- Advertisement -

EXPLORE MORE

CIA Chief's Moscow Trip Was About Iran, Not A NATO Warning: Estonia's Ex-President

Speculation has abounded over the nature of CIA Director John Ratcliffe's surprise Tuesday…

Record-breaking 31.4 Tbps DDoS attack hits in November 2025, stopped by Cloudflare

AISURU/Kimwolf botnet hit a record 31.4 Tbps DDoS attack lasting 35 seconds…

Ukraine’s STING S Downs Jet-Powered Geran-5 as Drone Air Defense Enters New Race

Ukraine’s 1020th Anti-Aircraft Missile Regiment publicly documented a combat interception of a…

ApolloMD data breach impacts 626,540 people

A May 2025 cyberattack on ApolloMD exposed the personal data of over…

Wanted: Suspect for Assault in the 9th District [VIDEO]

Central Detective Division is seeking the public’s help identifying the individual seen…

The login discovery relied heavily on residential proxies. Attackers used one large Azure IP for a big chunk of traffic, but the rest came from thousands of legitimate consumer IPs worldwide. Each IP had a unique browser fingerprint, helping them bypass geofencing and reputation filters.

The version check ran over six hours from 10 AWS IPs using the same old Chrome fingerprint. The rapid, focused activity suggests the attackers acted fast after finding potential targets.

The Azure scanner routed traffic through VPNs and tunnels with a slightly smaller-than-normal MSS, showing careful operational security. Residential proxies came from Windows devices but passed through Linux proxies, blending consumer traffic. AWS version scanners used jumbo frame settings only possible in datacenters, confirming they relied on dedicated infrastructure rather than consumer networks.

TCP analysis shows different infrastructure setups but a shared framework: Azure traffic used VPN tunnels, residential scans went through Linux proxies, and AWS scans required datacenter-level network settings. All shared TCP traits indicate the same underlying tools across campaigns.

“Despite different infrastructure types, all fingerprints share identical TCP option ordering, which is an indicator of common tooling or framework underneath the operational compartmentalization.” continues the report.

The reconnaissance likely maps Citrix infrastructure before attacks, targeting EPA setup files for potential exploits. Organizations should monitor unusual user agents, rapid login enumeration, outdated browser fingerprints, and external access to sensitive paths. Defense includes limiting exposure, enforcing authentication, suppressing version info, and flagging suspicious regional traffic.

“This reconnaissance activity likely represents infrastructure mapping before exploitation. The specific targeting of the EPA setup file path suggests interest in version-specific exploit development or vulnerability validation against known Citrix ADC weaknesses.” concludes the report that includes Indicators of Compromise (IoCs).

Pierluigi Paganini



Share This Article

China backs Cuba after Trump says island ‘will fall’

Beijing has vowed to support Havana against external interference…

Turkey Recruits Trump Insiders For New Washington Lobbying Push

Via Middle East Eye The Turkish government hired a lobbying firm…

SAUDI DEFENSE PAPER TIGER: FOREIGN CONTRACTORS AND INTEL LEAKS IN YEMEN

RIYADH — As geopolitical volatility escalates across the Arabian…

Why Russia Issued an Arrest Warrant for a Gay British Agitator

Caolan Robertson is an British YouTube video maker, amateur…

Zionism and the Ottoman Empire: The Final Step to Conquering Palestine

The final step, which lasted until the fall of…

The Iran War Has Turned VLCCs Into $650,000-A-Day Assets

Authored by Julianne Geiger via OilPrice.com, More Gulf oil…

Iran's Ghalibaf Declares Persian Gulf Oil Flows For 'All Or None'

Via The Cradle Iranian Parliament Speaker Mohammad Bagher Ghalibaf…

CONVERSATION

Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted