Anubis Affiliates Ride Citrix Bleed 2 Into Enterprise Networks

Ransomware crews are chaining CVE-2025-5777 with RMM tooling and stolen credentials to skip past MFA entirely.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: a dimly lit server rack in a data center with a single amber warning LED glowing on a network appliance
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Anubis ransomware affiliates are actively exploiting Citrix Bleed 2, tracked as CVE-2025-5777, for initial access into NetScaler ADC and Gateway appliances.
  • Affiliates are deploying legitimate Remote Management and Monitoring (RMM) tooling post-access to blend into normal admin traffic.
  • Operators are combining Citrix Bleed 2 exploitation with Bring Your Own Vulnerable Driver (BYOVD) techniques and supply-chain credential theft.
  • Citrix Bleed 2 leaks session material from unauthenticated appliance memory, allowing attackers to hijack authenticated sessions without triggering MFA.

Anubis is back on the initial-access treadmill, and the door this time is Citrix.

Affiliates tied to the ransomware operation are exploiting Citrix Bleed 2, the memory-disclosure flaw in NetScaler ADC and Gateway tracked as CVE-2025-5777, to plant themselves inside enterprise perimeters. The activity was documented across multiple incident responses, as reported by The Hacker News. When a proof-of-concept dropped, exploitation followed within hours, not days, as our CitrixBleed Redux piece from 2 July reported.

The pattern will feel familiar to anyone who lived through the original Citrix Bleed in 2023. Send an unauthenticated request, read whatever the appliance leaves in memory, sift out a valid session token, replay it.

That last step is the part defenders keep underestimating. When an attacker replays a stolen session cookie against a gateway, they inherit an already-authenticated context. No fresh login. No MFA prompt. Refresh-token rotation and any downstream OIDC assertions sit behind that session, so multi-factor at the front door does nothing here. This is a session-hijack problem, not an auth problem, and session binding is what would've stopped it.

What should defenders patch and hunt for first?

Citrix's fix for CVE-2025-5777 has been available since June, and the company's guidance is explicit that patching alone isn't enough. Administrators must also terminate all active ICA and PCoIP sessions on affected appliances after upgrading. Anything less leaves hijacked tokens valid.

Once inside, Anubis affiliates reach for legitimate tooling rather than dropping loud custom implants. Investigators observed commodity RMM software used for persistence and lateral movement, a tradecraft choice that dodges most EDR heuristics keyed on unsigned binaries. If your allowlist blesses AnyDesk or Atera by default, an operator with a valid session and a domain foothold looks a lot like your MSP.

Credential access is the second act. Hands-on-keyboard operators pulled secrets from memory, browser stores, and in some intrusions from third-party suppliers whose credentials granted onward access into the primary target. Supply-chain credential reuse is a recurring theme in 2025 ransomware casework.

The third ingredient is BYOVD. Affiliates load vulnerable signed drivers to disable endpoint protection before executing the ransomware payload. Microsoft's vulnerable driver blocklist helps, if it's actually enabled. Worth checking today rather than assuming. For a sense of how deliberately this capability is packaged, our 19 June story on The Gentlemen RaaS showed an affiliate program shipping a dedicated EDR killer with a kill list of roughly 400 security processes.

Should you run a fast hunt right now?

Yes. Four places to start:

  1. Review NetScaler appliance uptime. Any device that hasn't rebooted since the June patch window deserves scrutiny.
  2. Audit active ICA/PCoIP sessions and force termination if the appliance was patched without a session flush.
  3. Alert on RMM binaries executing from user profile paths or spawning cmd.exe and PowerShell with encoded arguments.
  4. Rotate credentials for any third-party integrator with standing access to Citrix-fronted environments.

Citrix Bleed 2 isn't clever. It's just effective, because session tokens remain the softest tissue in the modern identity stack. Until session binding to device or client posture becomes the default rather than the exception, this class of bug will keep paying rent for ransomware crews.

© 2026 Threat Vectr