{"id":1585,"date":"2026-07-02T20:53:07","date_gmt":"2026-07-02T20:53:07","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1585"},"modified":"2026-07-02T20:53:07","modified_gmt":"2026-07-02T20:53:07","slug":"ransomware-groups-turn-to-citrix-bleed-2-byovd-and-supply-chain-credentials","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1585","title":{"rendered":"Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh5gkjf1FwB4__nC6-pLZYnDv2rJA29UAL9mxfCv4BNSl1FxNpat9jD-OiMRLewjXJXyiSGvqiLYcewN_b1lLFHh0FhzKkrHFzu82jziSuOodYX87FkwjuCcXaqwzWRsiFdsBcd9mzDnak1rJpDu46F8TV206IEcD1pE7njojB8TcQEZ4Wa70KnK2vyeVKI\/s1700-e365\/ransomwares.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Threat actors associated with the <b>Anubis<\/b> ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access.<\/p>\n<p>\u00abAlthough tactics differ between affiliates, common patterns emerged in tradecraft through use of legitimate Remote Management and Monitoring (RMM) tooling, credential access, and hands-on-keyboard procedures used for lateral movement,\u00bb Arctic Wolf <a href=\"https:\/\/arcticwolf.com\/resources\/blog\/citrixbleed-2-to-cloudflared-the-tools-and-techniques-behind-anubis-ransomware-attacks\/\">said<\/a> in a report published this week.<\/p>\n<p>\u00abAnubis affiliates repeatedly abused legitimate remote access and administration tools, including ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, and Total Software Deployment, to blend in with normal IT activity while maintaining control of victim systems.\u00bb<\/p>\n<p>Anubis is a ransomware-as-a-service (RaaS) group that first emerged in late 2024 as a rebrand of Sphinx ransomware. The ransomware operation was formally announced on the Ransomware and Advanced Malware Protection (RAMP) underground forum in February 2025. According to <a href=\"https:\/\/ransomware.live\/group\/anubis\">data<\/a> from Ransomware.Live, the cybercrime crew has claimed 91 victims on its data leak site, with 11 victims reported in June 2026 alone.<\/p>\n<p>Some of the prominent sectors targeted include healthcare, business services, manufacturing, technology, and financial services. More than 50% of the victims are located in the U.S., followed by the U.K., Australia, France, and Canada.<\/p>\n<p>In a report published in July 2025, Rubrik Zero Labs said Anubis advertises attractive profit splits, offering affiliates 80% of the ransom amounts paid, and pairs it with an irreversible data-wiping feature that ups the pressure on victims to pay up.<\/p>\n<p>\u00abWhen Anubis&#8217;s \/WIPEMODE module is activated, files remain in directories but are reduced to a 0 KB size regardless of ransom payment,\u00bb Rubrik <a href=\"https:\/\/zerolabs.rubrik.com\/blog\/anubis-ransomware-stresses-need-advanced-data-backup\">noted<\/a> at the time. \u00abKnowing threat actors can revert victims&#8217; environments to this scorched-earth state with a single command significantly increases pressure on victims to pay before the wiper is fully activated.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The ransomware intrusions, observed this year, involve both valid VPN credential use and the exploitation of CVE-2025-5777 (CVSS score: 9.3), a critical flaw impacting Citrix NetScaler ADC and Gateway that could be abused by an attacker to bypass authentication when the appliance is configured as a Gateway or AAA virtual server.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The exact source of VPN credentials used in these intrusions is unknown. However, it&#8217;s possible they were procured following prior compromise, or through initial access brokers (IABs), credential stuffing, or information stealer activity.<\/p>\n<p>\u00abIn addition to CitrixBleed 2 exploitation, valid Cisco AnyConnect VPN logins were observed from several hosting ASNs, including AS20473 \u2014 The Constant Company and AS55286 \u2014 ServerMania,\u00bb Arctic Wolf explained. \u00abMalicious VPN authentication was then followed by login activity involving RDP and SMB, leading to credential access, PsExec service creation, RMM deployment, and ultimately invoking cloud-transfer tooling for exfiltration.\u00bb<\/p>\n<p>Lateral movement is facilitated via RDP and PsExec, which then leads to the deployment of various legitimate RMM tools for persistent access, granting the attackers the ability to transfer files and remotely execute code, while staying under the radar. Select intrusions also configure a Cloudflare Tunnel (aka cloudflared) to establish tunnels to victim environments.<\/p>\n<p>The next phase of the attacks involves gathering credentials to facilitate deeper access to the compromised environment, after which tools like S3 Browser, rclone, s5cmd, WinSCP, and PuTTY are installed for data transfer or exfiltration prior to ransomware deployment. In parallel, steps are taken to impair system defenses and complicate post-incident analysis.<\/p>\n<p>\u00abThese techniques included Windows Defender real-time protection disablement, SophosUninstall activity, PCHunter-related artifacts, and log clearing or manipulation across multiple systems,\u00bb the cybersecurity company explained. \u00abIn at least one intrusion, an Anubis encryptor was deleted after execution, reducing the availability of on-disk payload artifacts for later analysis.\u00bb<\/p>\n<h3>The Gentlemen&#8217;s Go Backdoor and 0-Day Exploit Detailed<\/h3>\n<p>The disclosure comes as Kaspersky detailed <b><a href=\"https:\/\/zerolabs.rubrik.com\/blog\/under-hood-deconstructing-gentlemen-esxi-ransomware\">The Gentlemen<\/a><\/b> RaaS group&#8217;s exploitation of known vulnerabilities and stolen or weak login credentials to breach targets and its use of a Go-based backdoor to enable remote command execution after reconnaissance, lateral movement through Group Policy or PsExec, and defense evasion using the bring your own vulnerable driver (BYOVD) technique.<\/p>\n<p>The implant is designed to collect system information, exfiltrate it to an external server (\u00ab81.177.215[.]15:9443\u00bb) over a bidirectional TCP connection, and await operator responses that are then executed on the host using \u00abcmd.exe\u00bb if the response byte is \u00abc.\u00bb If the byte is \u00abs,\u00bb a SOCKS proxy connection is established.<\/p>\n<p>\u00abThis functionality likely enables The Gentlemen&#8217;s red team to pivot within the target network and expand their scan coverage,\u00bb Kaspersky <a href=\"https:\/\/securelist.com\/the-gentlemen-raas\/120447\/\">said<\/a>. \u00abGiven the backdoor implant\u2019s capabilities, such as establishing two-way communication, executing commands, setting up a SOCKS proxy, and gathering information, it&#8217;s clear that it can also be used to expand the attack chain as needed.\u00bb<\/p>\n<p>According to Expel, the RaaS group has also weaponized a zero-day vulnerability in a little-known third-party vendor driver as part of its BYOVD arsenal to obtain kernel-level access, bypass Windows security protections, and kill protected security processes associated with Microsoft, ESET, Palo Alto Networks, and SentinelOne. The driver in question is <a href=\"https:\/\/www.kontron.com\/download\/download?filename=\/downloads\/tools\/ktd-00798-c-kt-api-v2-dll-user-manual.pdf&amp;product=89765\">ktapi.sys<\/a>, which is part of an API developed by Kontron.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/sygnia-cyber-response-d-1\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiqmM4NpfZsx4cw-HrXQlCjZQmrF8bYnmB23AmpOPi16kPNB9lvICjpdYEclxJwyQ9OE8GgzQ8aOEI68tRuxNqov0MHz2Sq8xEPiYWM3Js6FM5t2nm2JHWodmR7qVSot14ZtWVqQRQ6B88OnMaVxCPwRG7xGPoIIZxF6QAhWVhMkQfs11NjyNtHsGEUH4_q\/s728-e100\/sygnia-d-1.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abIt&#8217;s still unclear how the threat actors came into possession of the file or gained knowledge of its vulnerability,\u00bb Marcus Hutchins <a href=\"https:\/\/expel.com\/blog\/not-very-gentlemanly-analyzing-a-zero-day-exploit-used-by-the-gentlemen-ransomware-to-disable-targets-edrs\/\">said<\/a>. \u00abBYOVD continues to be a huge threat to enterprises, enabling attackers to disable state-of-the-art endpoint security systems in seconds. Even using the latest Windows version, with all exploit mitigations enabled, does not provide complete protection.\u00bb<\/p>\n<h3>VECT and TeamPCP&#8217;s Ransomware Partnership<\/h3>\n<p>The findings also follow an investigation from Sophos Counter Threat Unit into the partnership between <b>VECT<\/b> and TeamPCP that was announced in March 2026 to combine supply chain attack-driven credential theft with ransomware deployment.<\/p>\n<p>\u00abThe formal partnership between TeamPCP and VECT allows VECT to deploy ransomware across all organizations compromised in the Trivy and LiteLLM supply chain attacks,\u00bb Sophos said in a report shared with The Hacker News. \u00abPrior to the VECT partnership, TeamPCP was running another ransomware operation under the CipherForce brand. CipherForce listed six victims on its leak site in February 2026 and rebranded as a TeamPCP leak site in May.\u00bb<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg8zHosFGAqmsU95fSK0oy04UQWajROoipsu9KpevPUUBj4sEjMuZOv-7Hml366Zt9soN5NLC7nWC-EAiHZ1dSU-exht6WJ21ncbNDxO5BHhz0_x8T9rfhyphenhyphenB1_TqB3ocZyUZQcel_ZlccoMLSO4tzBYxl1xZWjKtMVGyv5yFKUWiCuJNWl0DpPgnFkXo-Sr\/s1700-e365\/partnerships.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg8zHosFGAqmsU95fSK0oy04UQWajROoipsu9KpevPUUBj4sEjMuZOv-7Hml366Zt9soN5NLC7nWC-EAiHZ1dSU-exht6WJ21ncbNDxO5BHhz0_x8T9rfhyphenhyphenB1_TqB3ocZyUZQcel_ZlccoMLSO4tzBYxl1xZWjKtMVGyv5yFKUWiCuJNWl0DpPgnFkXo-Sr\/s1700-e365\/partnerships.png\" alt=\"\" border=\"0\" data-original-height=\"559\" data-original-width=\"893\"\/><\/a><\/div>\n<p>Recent analyses from Check Point and <a href=\"https:\/\/www.jumpsec.com\/guides\/vect-ransomware-analysis\/\">JUMPSEC<\/a> have found VECT to contain implementation flaws that cause any file larger than 128 KB to be permanently destroyed rather than encrypted, prompting TeamPCP to issue a statement stating they had never used VECT&#8217;s encryptor in attacks. \u00abWe own CipherForce, our own private locker,\u00bb the group claimed.<\/p>\n<p>\u00abThe Vect\/TeamPCP alliance represents a meaningful shift in the ransomware threat landscape, even accounting for the technical shortcomings that undermine its operational effectiveness,\u00bb Sophos <a href=\"https:\/\/www.sophos.com\/en-us\/blog\/vect-and-teampcp-partner-for-ransomware-campaigns\">said<\/a>.<\/p>\n<p>\u00abThe convergence of large-scale supply chain credential theft, a maturing RaaS operation, and mass underground forum mobilization constitutes an unprecedented model of industrialized ransomware deployment that significantly lowers the barrier to entry for cybercrime.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access. \u00abAlthough tactics differ between affiliates, common patterns emerged&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1586,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[2318,119,219,764,446,1499,93,218,2317],"class_list":["post-1585","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-bleed","tag-byovd","tag-chain","tag-citrix","tag-credentials","tag-groups","tag-ransomware","tag-supply","tag-turn"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1585","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1585"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1585\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1586"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1585"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1585"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1585"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}