Malicious actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 vulnerability (CVE-2025-5777) to gain initial access.
See also: FortiBleed: Credential theft linked to INC and Lynx Ransomware

“While tactics vary among partners, common patterns emerged in the technique through the use of legitimate Remote Management and Monitoring (RMM) tools, credential access, and direct keystroke procedures used for lateral movement,” Arctic Wolf said in a report published this week.
“Anubis operatives repeatedly exploited legitimate remote access and management tools, including ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, and Total Software Deployment, to integrate with normal IT activity while maintaining control of victims' systems.“
Anubis is a ransomware-as-a-service (RaaS) that first appeared in late 2024 as a repurposing of the Sphinx ransomware. The ransomware operation was officially announced on the underground Ransomware and Advanced Malware Protection (RAMP) in February 2025. According to data from Ransomware.Live, the criminal group has claimed 91 victims on its data leak site, with 11 victims reported in June 2026 alone.
Some of the major sectors targeted include healthcare, business services, manufacturing, technology, and financial services. More than 50% of victims are in the U.S., followed by the U.K., Australia, France, and Canada.
In a report published in July 2025, Rubrik Zero Labs said that Anubis advertises attractive profit splits, offering affiliates 80% of ransom amounts paid, and combines this with an irreversible data deletion feature that increases the pressure on victims to pay.
“When Anubis’ /WIPEMODE module is activated, files remain in the directories but are reduced to 0 KB in size regardless of ransom payment,” Rubrik noted at the time. “Knowing that malicious actors can restore victims’ environments to this scorched-earth state with a single command significantly increases the pressure on victims to pay up before the wiper is fully activated.”
See also: Citrix Bleed 2: Added to CISA's KEV List

Ransomware attacks observed this year include both the use of valid VPN credentials and the exploitation of CVE-2025-5777 (CVSS score: 9.3), a critical vulnerability affecting Citrix NetScaler ADC and Gateway that could be used by an attacker to bypass authentication when the device is configured as a Gateway or AAA virtual server.
The exact source of the VPN credentials used in these intrusions is unknown, however, it is possible that they were obtained after a previous breach, or through initial access brokers (IABs), credential stuffing attacks, or information theft activity.
“In addition to the CitrixBleed 2 exploit, valid Cisco AnyConnect VPN connections were observed from several hosting ASNs, including AS20473 — The Constant Company and AS55286 — ServerMania,” Arctic Wolf explained. “The malicious VPN authentication was followed by connection activity involving RDP and SMB, leading to access to credentials, creation of a PsExec service, deployment of RMM, and ultimately triggering cloud-based transport tools for data extraction.”
Lateral movement is facilitated via RDP and PsExec, which then leads to the deployment of various legitimate RMM tools for persistent access, allowing attackers to transfer files and execute code remotely while remaining under the radar. Select exploits also configure a Cloudflared Tunnel (also known as cloudflared) to tunnel into victims' environments.
The next phase of the attacks involves gathering credentials to facilitate deeper access to the compromised environment, after which tools such as S3 Browser, rclone, s5cmd, WinSCP , and PuTTY to transfer or extract data before deploying the ransomware. At the same time, measures are taken to weaken the system’s defenses and complicate post-incident analysis.
See also: US hospitals urged to protect against Citrix Bleed bug
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

“These techniques included disabling Windows Defender real-time protection, SophosUninstall activity, PCHunter-related objects, and cleaning or manipulating logs on multiple systems,” the cybersecurity firm explained.
