As cited
Copy frozen at (site build).
ransomware
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
Anubis ransomware operators are exploiting the Citrix Bleed 2 vulnerability (CVE-2025-5777) to gain initial access to targets. The group employs common tactics including legitimate Remote Management and Monitoring tools, credential harvesting, and manual lateral movement techniques.
Why it matters: Citrix Bleed 2 is an active attack vector for ransomware groups; defenders should prioritize patching and monitoring for exploitation attempts and suspicious RMM tool activity.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
Anubis ransomware operators are exploiting the Citrix Bleed 2 vulnerability (CVE-2025-5777) to gain initial access to targets. The group employs common tactics including legitimate Remote Management and Monitoring tools, credential harvesting, and manual lateral movement techniques.
Why it matters: Citrix Bleed 2 is an active attack vector for ransomware groups; defenders should prioritize patching and monitoring for exploitation attempts and suspicious RMM tool activity.
- Source published
- First seen by Cybersecurity Tracker