Threat reportThreat IntelligenceTL-2026-0061
Citrix NetScaler Mass Reconnaissance Campaign via Residential Proxies
Citrix NetScaler Mass Reconnaissance Campaign via (TL-2026-0061), also tracked as CitrixBleed 2, is a high-severity tracked intrusion set scored CVSS 8.1, first published 2026-02-03. It carries a reported China nexus and is not formally attributed, affects Citrix NetScaler ADC, references 2 CVEs (CVE-2025-5777, CVE-2025-5775), maps to 20 MITRE ATT&CK techniques (T1005, T1021, T1027), and is covered by 7 detection rules and 34 indicators of compromise.
- CVSS
- 8.1/10High
- CVEs
- 2Referenced vulnerabilities
- Techniques
- 20MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 7SPL · KQL · Sigma
- IOCs
- 34Indicators of compromise
Key facts for TL-2026-0061
- Threat ID
- TL-2026-0061
- Also known as
- CitrixBleed 2
- Severity
- HIGH
- CVSS
- 8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution confidence
- NONE
- Nation-state nexus
- China
- Motivation
- MIXED
- Target sectors
- Government, Critical Infrastructure, Healthcare, Finance, Technology, All Organizations Using Citrix NetScaler
- Target regions
- Global, North America, Europe, Asia Pacific
- Detection rules
- 7
- Indicators of compromise
- 34
Malware and tooling in Citrix NetScaler Mass Reconnaissance Campaign via
Malware and tooling: NPS tunneler (ehang-io/nps v0.26.10) with filename 'npc'
How Citrix NetScaler Mass Reconnaissance Campaign via works
A sustained mass reconnaissance and exploitation campaign targets Citrix NetScaler ADC and Gateway appliances through residential proxy networks to evade IP-based blocking and rate limiting. The campaign systematically scans the internet for vulnerable NetScaler instances, exploiting CVE-2023-3519 (unauthenticated RCE, CVSS 9.8), CVE-2023-4966 'Citrix Bleed' (session token information disclosure, CVSS 9.4), and CVE-2024-6677/6678 (privilege escalation and authentication bypass). Attackers route scanning traffic through residential proxy networks (including infrastructure documented in TL-2026-0011 IPIDEA) to distribute probes across thousands of unique residential IPs, making traditional IP-based blocking, rate limiting, and reputation scoring ineffective. Post-exploitation involves web shell deployment (SECRETSAUCE PHP web shells, REGEORG.NEO tunnelers), configuration theft (ns.conf with encrypted secrets and TLS private keys), credential harvesting via session token theft (Citrix Bleed), and lateral movement into enterprise networks. Mandiant attributed early exploitation to suspected espionage actors, while subsequent mass exploitation campaigns have been attributed to financially motivated groups including ransomware operators (LockBit). Over 2,000 NetScaler instances were backdoored in mass exploitation waves. Shadowserver Foundation tracked thousands of vulnerable instances globally.
Citrix NetScaler ADC (Application Delivery Controller) and Gateway are enterprise edge devices that provide load balancing, SSL VPN, and application firewall capabilities. They sit at the network perimeter, making them high-value targets — compromising a NetScaler appliance gives attackers a foothold inside the enterprise network perimeter, bypassing traditional defenses.
**The Residential Proxy Reconnaissance Problem:**
Traditional scanning campaigns use datacenter IPs that are easily blocked by firewall rules and IP reputation services. The Citrix NetScaler scanning campaign evolved to use residential proxy networks — routing probes through millions of legitimate residential IP addresses. This makes the scanning traffic appear to originate from normal home internet users rather than known-malicious infrastructure.
Key characteristics: - Scanning distributed across thousands of unique residential IPs per campaign - Each IP sends only a few probes (below rate-limit thresholds) - Residential IPs have clean reputation scores (not in threat feeds) - IP-based blocking is futile — new residential IPs are available endlessly - Geographic distribution matches normal traffic patterns (not concentrated in hosting regions) - Connection to IPIDEA and similar residential proxy services (TL-2026-0011)
**CVE-2023-3519 — Unauthenticated RCE (CVSS 9.8):**
Disclosed July 2023. Allows unauthenticated remote code execution on NetScaler ADC and Gateway configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Mandiant identified exploitation by suspected espionage actors:
1. Initial exploitation via specially crafted HTTP request 2. PHP eval web shell deployed to /var/vpn/themes/ (113 bytes) 3. Configuration theft: ns.conf + F1/F2 encryption keys 4. SECRETSAUCE web shells deployed (RSA-encrypted command channels) 5. REGEORG.NEO tunneler for SOCKS proxy access 6. Persistent tunneler (ligolo-ng derivative) with crontab persistence 7. NPS tunneler for additional access capabilities 8. Setuid bash binary created for root privilege escalation
Mandiant assessed with moderate confidence that a China-nexus espionage actor was responsible for early exploitation. CISA added CVE-2023-3519 to the KEV catalog.
**CVE-2023-4966 'Citrix Bleed' (CVSS 9.4):**
Disclosed October 2023. Information disclosure vulnerability that leaks session tokens from NetScaler ADC and Gateway memory. Attackers exploit this to hijack authenticated sessions without credentials:
1. Send specially crafted HTTP request to vulnerable endpoint 2. NetScaler returns session token in response (buffer over-read) 3. Attacker replays stolen session token to bypass MFA and authentication 4. Full VPN access to enterprise network as the hijacked user 5. Lateral movement, data exfiltration, ransomware deployment
Citrix Bleed was exploited by LockBit ransomware affiliates (Boeing breach), Medusa ransomware, and multiple APT groups. Proof of concept was published on Packet Storm Security. CISA issued emergency directive.
**Mass Exploitation Scale:** - Shadowserver Foundation tracked 2,000+ backdoored NetScaler instances - Tens of thousands of NetScaler ADC/Gateway appliances exposed to internet globally - CISA issued advisory AA23-201A for CVE-2023-3519 - CVE-2023-4966 exploited within days of PoC publication - Residential proxy scanning made patching race impossible — attackers identified and exploited vulnerable instances faster than organizations could patch
**Post-Exploitation TTPs:** - Web shell deployment in /var/vpn/themes/ directory - Configuration file theft (ns.conf contains LDAP bind passwords, RADIUS secrets, SAML certificates) - TLS private key theft enabling decryption of encrypted traffic - Active Directory credential harvesting via LDAP - Kerberoasting from NetScaler management IP addresses - VPN session hijacking for persistent access - Ransomware deployment via compromised VPN tunnels
MITRE ATT&CK techniques used in TL-2026-0061
collection
lateral-movement
defense-evasion
T1027 Obfuscated Files or Information; T1070 Indicator Removal
exfiltration
T1041 Exfiltration Over C2 Channel
discovery
T1046 Network Service Discovery
execution
T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution
command-and-control
T1090 Proxy; T1572 Protocol Tunneling
initial-access
T1190 Exploit Public-Facing Application
impact
T1486 Data Encrypted for Impact
persistence
T1505 Server Software Component
credential-access
T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1558 Steal or Forge Kerberos Tickets
privilege-escalation
T1548 Abuse Elevation Control Mechanism
resource-development
T1584 Compromise Infrastructure
reconnaissance
Affected products and versions in Citrix NetScaler Mass Reconnaissance Campaign via
Remediation for Citrix NetScaler Mass Reconnaissance Campaign via
Patches
- Apply latest Citrix NetScaler ADC security updates
Immediate actions
- Review necessity of internet-facing Citrix Gateways
- Restrict access to /epa/scripts/ directory
- Implement geo-blocking for unexpected regions
- Enable rate limiting on Citrix Gateway endpoints
Workarounds
- Block Chrome 50 user agent at WAF
- Block blackbox-exporter user agent
Longer-term hardening
- Disable version disclosure in HTTP responses
- Deploy WAF rules for enumeration patterns
- Monitor for residential IP traffic anomalies
- Patch CVE-2025-5777 and CVE-2025-5775 immediately
CVEs associated with Citrix NetScaler Mass Reconnaissance Campaign via
Weaknesses (CWE) in Citrix NetScaler Mass Reconnaissance Campaign via
Timeline of Citrix NetScaler Mass Reconnaissance Campaign via
- Citrix publishes security bulletin CTX561482 disclosing CVE-2023-3519 (CVSS 9.8, unauthenticated RCE), CVE-2023-3467 (privilege escalation), and CVE-2023-3466 (XSS) in NetScaler ADC and Gateway. Citrix confirms active exploitation in the wild. Source: https://support.citrix.com/article/CTX561482
- Mandiant publishes analysis of CVE-2023-3519 exploitation by suspected China-nexus espionage actor. TTPs include PHP eval web shell (113 bytes), SECRETSAUCE web shells with RSA encryption, REGEORG.NEO tunneler, ligolo-ng persistent tunneler, ns.conf theft with encryption keys. CISA issues advisory AA23-201A. Source: https://cloud.google.com/blog/topics/threat-intelligence/citrix-zero-day-espionage/
- Shadowserver Foundation reports over 2,000 NetScaler instances confirmed backdoored from mass exploitation campaign. Scanning traffic routed through residential proxy networks to evade IP-based blocking. Scale far exceeds initial espionage targeting — now financially motivated groups involved. Source: https://www.shadowserver.org/
- Citrix discloses CVE-2023-4966 'Citrix Bleed' (CVSS 9.4) — session token information disclosure via buffer over-read in NetScaler ADC and Gateway. Exploitation allows session hijacking bypassing MFA. PoC published on Packet Storm Security within weeks. Source: https://nvd.nist.gov/vuln/detail/CVE-2023-4966
- LockBit ransomware affiliates exploit Citrix Bleed (CVE-2023-4966) in Boeing breach and multiple enterprise targets. Medusa ransomware also adopts the exploit. CISA issues emergency directive. Session token theft enables VPN access bypassing all authentication controls including MFA.
- Mass reconnaissance campaign using residential proxy networks (IPIDEA, 911 S5 successors) systematically scans internet for remaining vulnerable NetScaler instances. Residential IPs evade IP reputation and rate limiting. Campaign identifies and exploits instances within hours of vulnerability disclosure. Connection to TL-2026-0011 (IPIDEA residential proxy network).
- As of 2026-05-29, this NetScaler campaign is ACTIVE despite a "PATCHED" record: CVE-2025-5777 (CitrixBleed 2) is in CISA KEV with millions of ongoing exploitation attempts (Imperva), and GreyNoise tracked a fresh ~63K residential-proxy scanning wave Jan 28-Feb 2 2026. It is evolving onto successor CVE-2026-3055 (watchTowr recon, Mar 2026), so it has not concluded.
Sources cited for Citrix NetScaler Mass Reconnaissance Campaign via
- Mandiant — Exploitation of Citrix Zero-Day by Possible Espionage Actors (CVE-2023-3519)
- NVD — CVE-2023-4966 (Citrix Bleed)
- CISA Advisory AA23-201A — CVE-2023-3519
- Citrix CTX561482 — CVE-2023-3519 Bulletin
- Citrix CTX579459 — CVE-2023-4966 Bulletin
- Packet Storm — Citrix Bleed PoC
- Shadowserver Foundation — NetScaler Exploitation Tracking
- MITRE ATT&CK — Exploit Public-Facing Application (T1190)
Detection coverage for TL-2026-0061
As of 2026-02-03, Threadlinqs Intelligence publishes 7 detection rule(s) for TL-2026-0061 across Splunk SPL, Microsoft KQL and Sigma, covering 34 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.