# Citrix NetScaler Mass Reconnaissance Campaign via Residential Proxies

> A sustained mass reconnaissance and exploitation campaign targets Citrix NetScaler ADC and Gateway appliances through residential proxy networks to evade IP-based blocking and rate limiting. The campaign systematically scans the internet for vulnerable NetScaler instances, exploiting CVE-2023-3519 (unauthenticated RCE, CVSS 9.8), CVE-2023-4966 'Citrix Bleed' (session token information disclosure, CVSS 9.4), and CVE-2024-6677/6678 (privilege escalation and authentication bypass). Attackers route scanning traffic through residential proxy networks (including infrastructure documented in TL-2026-0011 IPIDEA) to distribute probes across thousands of unique residential IPs, making traditional IP-based blocking, rate limiting, and reputation scoring ineffective. Post-exploitation involves web shell deployment (SECRETSAUCE PHP web shells, REGEORG.NEO tunnelers), configuration theft (ns.conf with encrypted secrets and TLS private keys), credential harvesting via session token theft (Citrix Bleed), and lateral movement into enterprise networks. Mandiant attributed early exploitation to suspected espionage actors, while subsequent mass exploitation campaigns have been attributed to financially motivated groups including ransomware operators (LockBit). Over 2,000 NetScaler instances were backdoored in mass exploitation waves. Shadowserver Foundation tracked thousands of vulnerable instances globally.

- **Published:** 2026-02-03T20:28:00Z
- **Last reviewed:** 2026-02-03T20:28:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0061
- **ID:** TL-2026-0061
- **Severity:** HIGH (CVSS 8.1)
- **Category:** THREAT_INTEL
- **Status:** ACTIVE
- **Detections:** 7 · **IOCs:** 34 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-5777, CVE-2025-5775

## Description

Citrix NetScaler ADC (Application Delivery Controller) and Gateway are enterprise edge devices that provide load balancing, SSL VPN, and application firewall capabilities. They sit at the network perimeter, making them high-value targets — compromising a NetScaler appliance gives attackers a foothold inside the enterprise network perimeter, bypassing traditional defenses.

**The Residential Proxy Reconnaissance Problem:**

Traditional scanning campaigns use datacenter IPs that are easily blocked by firewall rules and IP reputation services. The Citrix NetScaler scanning campaign evolved to use residential proxy networks — routing probes through millions of legitimate residential IP addresses. This makes the scanning traffic appear to originate from normal home internet users rather than known-malicious infrastructure.

Key characteristics:
- Scanning distributed across thousands of unique residential IPs per campaign
- Each IP sends only a few probes (below rate-limit thresholds)
- Residential IPs have clean reputation scores (not in threat feeds)
- IP-based blocking is futile — new residential IPs are available endlessly
- Geographic distribution matches normal traffic patterns (not concentrated in hosting regions)
- Connection to IPIDEA and similar residential proxy services (TL-2026-0011)

**CVE-2023-3519 — Unauthenticated RCE (CVSS 9.8):**

Disclosed July 2023. Allows unauthenticated remote code execution on NetScaler ADC and Gateway configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Mandiant identified exploitation by suspected espionage actors:

1. Initial exploitation via specially crafted HTTP request
2. PHP eval web shell deployed to /var/vpn/themes/ (113 bytes)
3. Configuration theft: ns.conf + F1/F2 encryption keys
4. SECRETSAUCE web shells deployed (RSA-encrypted command channels)
5. REGEORG.NEO tunneler for SOCKS proxy access
6. Persistent tunneler (ligolo-ng derivative) with crontab persistence
7. NPS tunneler for additional access capabilities
8. Setuid bash binary created for root privilege escalation

Mandiant assessed with moderate confidence that a China-nexus espionage actor was responsible for early exploitation. CISA added CVE-2023-3519 to the KEV catalog.

**CVE-2023-4966 'Citrix Bleed' (CVSS 9.4):**

Disclosed October 2023. Information disclosure vulnerability that leaks session tokens from NetScaler ADC and Gateway memory. Attackers exploit this to hijack authenticated sessions without credentials:

1. Send specially crafted HTTP request to vulnerable endpoint
2. NetScaler returns session token in response (buffer over-read)
3. Attacker replays stolen session token to bypass MFA and authentication
4. Full VPN access to enterprise network as the hijacked user
5. Lateral movement, data exfiltration, ransomware deployment

Citrix Bleed was exploited by LockBit ransomware affiliates (Boeing breach), Medusa ransomware, and multiple APT groups. Proof of concept was published on Packet Storm Security. CISA issued emergency directive.

**Mass Exploitation Scale:**
- Shadowserver Foundation tracked 2,000+ backdoored NetScaler instances
- Tens of thousands of NetScaler ADC/Gateway appliances exposed to internet globally
- CISA issued advisory AA23-201A for CVE-2023-3519
- CVE-2023-4966 exploited within days of PoC publication
- Residential proxy scanning made patching race impossible — attackers identified and exploited vulnerable instances faster than organizations could patch

**Post-Exploitation TTPs:**
- Web shell deployment in /var/vpn/themes/ directory
- Configuration file theft (ns.conf contains LDAP bind passwords, RADIUS secrets, SAML certificates)
- TLS private key theft enabling decryption of encrypted traffic
- Active Directory credential harvesting via LDAP
- Kerberoasting from NetScaler management IP addresses
- VPN session hijacking for persistent access
- Ransomware deployment via compromised VPN tunnels

## MITRE ATT&CK

- T1595 Active Scanning
- T1584 Compromise Infrastructure
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1203 Exploitation for Client Execution
- T1505 Server Software Component
- T1053 Scheduled Task/Job
- T1548 Abuse Elevation Control Mechanism
- T1027 Obfuscated Files or Information
- T1070 Indicator Removal
- T1539 Steal Web Session Cookie
- T1552 Unsecured Credentials
- T1558 Steal or Forge Kerberos Tickets
- T1046 Network Service Discovery
- T1021 Remote Services
- T1005 Data from Local System
- T1572 Protocol Tunneling
- T1090 Proxy
- T1041 Exfiltration Over C2 Channel
- T1486 Data Encrypted for Impact

## Sources

- [Mandiant — Exploitation of Citrix Zero-Day by Possible Espionage Actors (CVE-2023-3519)](https://cloud.google.com/blog/topics/threat-intelligence/citrix-zero-day-espionage/)
- [NVD — CVE-2023-4966 (Citrix Bleed)](https://nvd.nist.gov/vuln/detail/CVE-2023-4966)
- [CISA Advisory AA23-201A — CVE-2023-3519](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-201a)
- [Citrix CTX561482 — CVE-2023-3519 Bulletin](https://support.citrix.com/article/CTX561482)
- [Citrix CTX579459 — CVE-2023-4966 Bulletin](https://support.citrix.com/article/CTX579459)
- [Packet Storm — Citrix Bleed PoC](http://packetstormsecurity.com/files/175323/Citrix-Bleed-Session-Token-Leakage-Proof-Of-Concept.html)
- [Shadowserver Foundation — NetScaler Exploitation Tracking](https://www.shadowserver.org/)
- [MITRE ATT&CK — Exploit Public-Facing Application (T1190)](https://attack.mitre.org/techniques/T1190/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0061
