Threat reportThreat IntelligenceTL-2026-0061

Citrix NetScaler Mass Reconnaissance Campaign via Residential Proxies

highACTIVE

Citrix NetScaler Mass Reconnaissance Campaign via (TL-2026-0061), also tracked as CitrixBleed 2, is a high-severity tracked intrusion set scored CVSS 8.1, first published 2026-02-03. It carries a reported China nexus and is not formally attributed, affects Citrix NetScaler ADC, references 2 CVEs (CVE-2025-5777, CVE-2025-5775), maps to 20 MITRE ATT&CK techniques (T1005, T1021, T1027), and is covered by 7 detection rules and 34 indicators of compromise.

CVSS
8.1/10High
CVEs
2Referenced vulnerabilities
Techniques
20MITRE ATT&CK
Actors
0Not attributed
Detection rules
7SPL · KQL · Sigma
IOCs
34Indicators of compromise

Key facts for TL-2026-0061

Threat ID
TL-2026-0061
Also known as
CitrixBleed 2
Severity
HIGH
CVSS
8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Status
ACTIVE
Category
THREAT_INTEL
First published
Last reviewed
Attribution confidence
NONE
Nation-state nexus
China
Motivation
MIXED
Target sectors
Government, Critical Infrastructure, Healthcare, Finance, Technology, All Organizations Using Citrix NetScaler
Target regions
Global, North America, Europe, Asia Pacific
Detection rules
7
Indicators of compromise
34

Malware and tooling in Citrix NetScaler Mass Reconnaissance Campaign via

Malware and tooling: NPS tunneler (ehang-io/nps v0.26.10) with filename 'npc'

How Citrix NetScaler Mass Reconnaissance Campaign via works

A sustained mass reconnaissance and exploitation campaign targets Citrix NetScaler ADC and Gateway appliances through residential proxy networks to evade IP-based blocking and rate limiting. The campaign systematically scans the internet for vulnerable NetScaler instances, exploiting CVE-2023-3519 (unauthenticated RCE, CVSS 9.8), CVE-2023-4966 'Citrix Bleed' (session token information disclosure, CVSS 9.4), and CVE-2024-6677/6678 (privilege escalation and authentication bypass). Attackers route scanning traffic through residential proxy networks (including infrastructure documented in TL-2026-0011 IPIDEA) to distribute probes across thousands of unique residential IPs, making traditional IP-based blocking, rate limiting, and reputation scoring ineffective. Post-exploitation involves web shell deployment (SECRETSAUCE PHP web shells, REGEORG.NEO tunnelers), configuration theft (ns.conf with encrypted secrets and TLS private keys), credential harvesting via session token theft (Citrix Bleed), and lateral movement into enterprise networks. Mandiant attributed early exploitation to suspected espionage actors, while subsequent mass exploitation campaigns have been attributed to financially motivated groups including ransomware operators (LockBit). Over 2,000 NetScaler instances were backdoored in mass exploitation waves. Shadowserver Foundation tracked thousands of vulnerable instances globally.

Citrix NetScaler ADC (Application Delivery Controller) and Gateway are enterprise edge devices that provide load balancing, SSL VPN, and application firewall capabilities. They sit at the network perimeter, making them high-value targets — compromising a NetScaler appliance gives attackers a foothold inside the enterprise network perimeter, bypassing traditional defenses.

**The Residential Proxy Reconnaissance Problem:**

Traditional scanning campaigns use datacenter IPs that are easily blocked by firewall rules and IP reputation services. The Citrix NetScaler scanning campaign evolved to use residential proxy networks — routing probes through millions of legitimate residential IP addresses. This makes the scanning traffic appear to originate from normal home internet users rather than known-malicious infrastructure.

Key characteristics: - Scanning distributed across thousands of unique residential IPs per campaign - Each IP sends only a few probes (below rate-limit thresholds) - Residential IPs have clean reputation scores (not in threat feeds) - IP-based blocking is futile — new residential IPs are available endlessly - Geographic distribution matches normal traffic patterns (not concentrated in hosting regions) - Connection to IPIDEA and similar residential proxy services (TL-2026-0011)

**CVE-2023-3519 — Unauthenticated RCE (CVSS 9.8):**

Disclosed July 2023. Allows unauthenticated remote code execution on NetScaler ADC and Gateway configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Mandiant identified exploitation by suspected espionage actors:

1. Initial exploitation via specially crafted HTTP request 2. PHP eval web shell deployed to /var/vpn/themes/ (113 bytes) 3. Configuration theft: ns.conf + F1/F2 encryption keys 4. SECRETSAUCE web shells deployed (RSA-encrypted command channels) 5. REGEORG.NEO tunneler for SOCKS proxy access 6. Persistent tunneler (ligolo-ng derivative) with crontab persistence 7. NPS tunneler for additional access capabilities 8. Setuid bash binary created for root privilege escalation

Mandiant assessed with moderate confidence that a China-nexus espionage actor was responsible for early exploitation. CISA added CVE-2023-3519 to the KEV catalog.

**CVE-2023-4966 'Citrix Bleed' (CVSS 9.4):**

Disclosed October 2023. Information disclosure vulnerability that leaks session tokens from NetScaler ADC and Gateway memory. Attackers exploit this to hijack authenticated sessions without credentials:

1. Send specially crafted HTTP request to vulnerable endpoint 2. NetScaler returns session token in response (buffer over-read) 3. Attacker replays stolen session token to bypass MFA and authentication 4. Full VPN access to enterprise network as the hijacked user 5. Lateral movement, data exfiltration, ransomware deployment

Citrix Bleed was exploited by LockBit ransomware affiliates (Boeing breach), Medusa ransomware, and multiple APT groups. Proof of concept was published on Packet Storm Security. CISA issued emergency directive.

**Mass Exploitation Scale:** - Shadowserver Foundation tracked 2,000+ backdoored NetScaler instances - Tens of thousands of NetScaler ADC/Gateway appliances exposed to internet globally - CISA issued advisory AA23-201A for CVE-2023-3519 - CVE-2023-4966 exploited within days of PoC publication - Residential proxy scanning made patching race impossible — attackers identified and exploited vulnerable instances faster than organizations could patch

**Post-Exploitation TTPs:** - Web shell deployment in /var/vpn/themes/ directory - Configuration file theft (ns.conf contains LDAP bind passwords, RADIUS secrets, SAML certificates) - TLS private key theft enabling decryption of encrypted traffic - Active Directory credential harvesting via LDAP - Kerberoasting from NetScaler management IP addresses - VPN session hijacking for persistent access - Ransomware deployment via compromised VPN tunnels

MITRE ATT&CK techniques used in TL-2026-0061

collection

T1005 Data from Local System

lateral-movement

T1021 Remote Services

defense-evasion

T1027 Obfuscated Files or Information; T1070 Indicator Removal

exfiltration

T1041 Exfiltration Over C2 Channel

discovery

T1046 Network Service Discovery

execution

T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution

command-and-control

T1090 Proxy; T1572 Protocol Tunneling

initial-access

T1190 Exploit Public-Facing Application

impact

T1486 Data Encrypted for Impact

persistence

T1505 Server Software Component

credential-access

T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1558 Steal or Forge Kerberos Tickets

privilege-escalation

T1548 Abuse Elevation Control Mechanism

resource-development

T1584 Compromise Infrastructure

reconnaissance

T1595 Active Scanning

Affected products and versions in Citrix NetScaler Mass Reconnaissance Campaign via

  • Citrix — NetScaler ADC
    Vulnerable versions: All versions
  • Citrix — NetScaler Gateway
    Vulnerable versions: All versions

Remediation for Citrix NetScaler Mass Reconnaissance Campaign via

Patches

  • Apply latest Citrix NetScaler ADC security updates

Immediate actions

  • Review necessity of internet-facing Citrix Gateways
  • Restrict access to /epa/scripts/ directory
  • Implement geo-blocking for unexpected regions
  • Enable rate limiting on Citrix Gateway endpoints

Workarounds

  • Block Chrome 50 user agent at WAF
  • Block blackbox-exporter user agent

Longer-term hardening

  • Disable version disclosure in HTTP responses
  • Deploy WAF rules for enumeration patterns
  • Monitor for residential IP traffic anomalies
  • Patch CVE-2025-5777 and CVE-2025-5775 immediately

CVEs associated with Citrix NetScaler Mass Reconnaissance Campaign via

CVE-2025-5777, CVE-2025-5775

Weaknesses (CWE) in Citrix NetScaler Mass Reconnaissance Campaign via

CWE-200

Timeline of Citrix NetScaler Mass Reconnaissance Campaign via

  • Citrix publishes security bulletin CTX561482 disclosing CVE-2023-3519 (CVSS 9.8, unauthenticated RCE), CVE-2023-3467 (privilege escalation), and CVE-2023-3466 (XSS) in NetScaler ADC and Gateway. Citrix confirms active exploitation in the wild. Source: https://support.citrix.com/article/CTX561482
  • Mandiant publishes analysis of CVE-2023-3519 exploitation by suspected China-nexus espionage actor. TTPs include PHP eval web shell (113 bytes), SECRETSAUCE web shells with RSA encryption, REGEORG.NEO tunneler, ligolo-ng persistent tunneler, ns.conf theft with encryption keys. CISA issues advisory AA23-201A. Source: https://cloud.google.com/blog/topics/threat-intelligence/citrix-zero-day-espionage/
  • Shadowserver Foundation reports over 2,000 NetScaler instances confirmed backdoored from mass exploitation campaign. Scanning traffic routed through residential proxy networks to evade IP-based blocking. Scale far exceeds initial espionage targeting — now financially motivated groups involved. Source: https://www.shadowserver.org/
  • Citrix discloses CVE-2023-4966 'Citrix Bleed' (CVSS 9.4) — session token information disclosure via buffer over-read in NetScaler ADC and Gateway. Exploitation allows session hijacking bypassing MFA. PoC published on Packet Storm Security within weeks. Source: https://nvd.nist.gov/vuln/detail/CVE-2023-4966
  • LockBit ransomware affiliates exploit Citrix Bleed (CVE-2023-4966) in Boeing breach and multiple enterprise targets. Medusa ransomware also adopts the exploit. CISA issues emergency directive. Session token theft enables VPN access bypassing all authentication controls including MFA.
  • Mass reconnaissance campaign using residential proxy networks (IPIDEA, 911 S5 successors) systematically scans internet for remaining vulnerable NetScaler instances. Residential IPs evade IP reputation and rate limiting. Campaign identifies and exploits instances within hours of vulnerability disclosure. Connection to TL-2026-0011 (IPIDEA residential proxy network).
  • As of 2026-05-29, this NetScaler campaign is ACTIVE despite a "PATCHED" record: CVE-2025-5777 (CitrixBleed 2) is in CISA KEV with millions of ongoing exploitation attempts (Imperva), and GreyNoise tracked a fresh ~63K residential-proxy scanning wave Jan 28-Feb 2 2026. It is evolving onto successor CVE-2026-3055 (watchTowr recon, Mar 2026), so it has not concluded.

Sources cited for Citrix NetScaler Mass Reconnaissance Campaign via

Detection coverage for TL-2026-0061

As of 2026-02-03, Threadlinqs Intelligence publishes 7 detection rule(s) for TL-2026-0061 across Splunk SPL, Microsoft KQL and Sigma, covering 34 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

7 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
34 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats