A large-scale reconnaissance operation targeting Citrix ADC Gateway and NetScaler Gateway infrastructure was detected between January 28 and February 2, 2026, by the GreyNoise Global Observation Grid. The coordinated operation involved residential proxy rotation for login panel discovery and concentrated AWS-hosted version disclosure scanning, generating over 111,834 sessions from more than 63,000 unique IP addresses. The campaign showcases sophisticated infrastructure-mapping capabilities, achieving a 79% targeting rate against Citrix Gateway honeypots, significantly surpassing baseline scanning noise and indicating deliberate reconnaissance rather than opportunistic crawling.

TCP-layer analysis revealed distinct infrastructure separation across the three attack components. The dominant Azure scanner showcased nested encapsulation with a reduced maximum segment size (MSS) 62 bytes below standard, revealing operators routed scanning traffic through an additional network layer for operational security.

AWS version scanners demonstrated jumbo frame MSS values 45 times larger than standard Ethernet allows, necessitating datacenter switching infrastructure with 9,000+ byte MTU support that is physically impossible on consumer networks. The targeted EPA setup file path indicates interest in version-specific exploit development or vulnerability validation against Citrix ADC weaknesses, particularly recent critical vulnerabilities enabling authentication bypass and remote code execution. Defensive recommendations include reviewing external Citrix Gateway exposure to validate business need for internet-facing deployments, implementing authentication requirements for the /epa/scripts/ directory, and configuring Citrix Gateways to suppress version disclosure in HTTP responses.