Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and Kontron Driver BYOVD for Access and Privilege Escalation
Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and (TL-2026-1086), also tracked as Citrix Bleed 2, is a critical-severity ransomware operation scored CVSS 9.3, first published 2026-07-02. It is attributed to Anubis with medium confidence, affects Citrix NetScaler ADC, references 1 CVE (CVE-2025-5777), maps to 31 MITRE ATT&CK techniques (T1005, T1016, T1018), and is covered by 9 detection rules and 28 indicators of compromise.
Key facts for TL-2026-1086
- Threat ID
- TL-2026-1086
- Also known as
- Citrix Bleed 2, CitrixBleed 2
- Severity
- CRITICAL
- CVSS
- 9.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N)
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-07-02
- Last reviewed
- 2026-07-02
- Attribution
- Anubis
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- health, business services, manufacturing, technology, financial services, critical infrastructure
- Target regions
- united states of america, united kingdom, australia, france, canada
- Detection rules
- 9
- Indicators of compromise
- 28
Malware and tooling in Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and
Malware and tooling: TeamPCP, anubis, the gentlemen, vect, MeshAgent, PuTTY, Rclone - S1040, Remotely, S3 Browser, ScreenConnect, Total Software Deployment, UltraVNC
Multiple ransomware-as-a-service operations, including Anubis, The Gentlemen, VECT, and TeamPCP (formerly CipherForce), are actively exploiting the Citrix Bleed 2 authentication bypass/memory-overread flaw (CVE-2025-5777, CVSS 9.3) in NetScaler ADC/Gateway for initial access, alongside a Bring Your Own Vulnerable Driver (BYOVD) technique abusing the Kontron ktapi.sys driver to blind EDR, and abuse of legitimate RMM tools (ScreenConnect, Zoho Assist, MeshAgent) for persistence.
How Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and works
Since June 2026, threat intelligence has confirmed active exploitation of CVE-2025-5777 ("Citrix Bleed 2"), a critical insufficient-input-validation vulnerability in Citrix NetScaler ADC and Gateway that produces a memory overread, allowing unauthenticated remote attackers to leak session tokens and other sensitive memory contents from vulnerable appliances. Leaked session tokens allow attackers to hijack authenticated sessions and bypass multi-factor authentication entirely, echoing the original 2023 CitrixBleed (CVE-2023-4966) flaw. CISA added CVE-2025-5777 to its Known Exploited Vulnerabilities (KEV) catalog on July 10, 2025, confirming in-the-wild exploitation; GreyNoise recorded a scanning/exploitation spike peaking around July 11, 2025 that has continued into 2026 as ransomware affiliates weaponize the flaw for initial access against internet-facing NetScaler Gateway/AAA virtual servers.
Anubis, a ransomware-as-a-service operation that emerged in late 2024 as a rebrand of the "Sphinx" prototype and formally launched in February 2025, has claimed 91 victims to date (11 in June 2026 alone), with over 50% of victims based in the United States and additional victims in the UK, Australia, France, and Canada, spanning healthcare, business services, manufacturing, technology, and financial services. Anubis is notable for an integrated destructive wiper capability (/WIPEMODE) that reduces files to 0 KB regardless of whether the ransom is paid, removing any recovery incentive even for paying victims. Anubis offers affiliates flexible monetization: an 80% payout RaaS model, a 40% cut extortion-assist model, and a 50% cut post-compromise extortion model.
The Gentlemen, first observed in mid-2025, has escalated its EDR-evasion tradecraft by deploying a zero-day BYOVD exploit against the Kontron ktapi.sys driver (previously undocumented as attacker tooling) to gain kernel-level access and disable EDR/antivirus protections, in addition to prior use of other vulnerable drivers (ProcessMonitorDriver.sys, wamsdk.sys, gamedriverx64.sys, biontdrv.sys, inpoutx64.sys, wsftprm.sys) as part of an EDR-killer framework capable of disabling 400+ security processes.
VECT, a newer ransomware strain, partnered with TeamPCP (the May 2026 rebrand of the CipherForce ransomware operation, which had claimed 6 victims as of February 2026) in March 2026. VECT's encryption implementation contains a flaw that permanently destroys files larger than 128KB, making recovery impossible even with a valid decryptor.
Across these campaigns, common post-exploitation TTPs include: abuse of valid VPN credentials (e.g., Cisco AnyConnect) for initial access alongside NetScaler exploitation; RDP/SMB-based lateral movement; PsExec for remote service creation; disabling of Windows Defender and uninstalling Sophos endpoint protection; clearing of Windows event logs; use of Cloudflare Tunnel (cloudflared) for covert network tunneling and C2; a Go-based backdoor with SOCKS proxy capability; and data exfiltration via S3 Browser, rclone, s5cmd, WinSCP, and PuTTY. Persistence is frequently established through abuse of legitimate remote monitoring and management (RMM) tools including ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, and Total Software Deployment, allowing attackers to blend into normal administrative traffic.
MITRE ATT&CK techniques used in TL-2026-1086
Collection
Discovery
T1016 System Network Configuration Discovery; T1018 Remote System Discovery
Lateral Movement
T1021.001 Remote Desktop Protocol; T1021.002 SMB/Windows Admin Shares
Execution
T1047 Windows Management Instrumentation; T1569.002 Service Execution
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application
Command and Control
T1090 Proxy; T1105 Ingress Tool Transfer; T1572 Protocol Tunneling
Defense Evasion
T1140 Deobfuscate/Decode Files or Information; T1211 Exploitation for Stealth
command-and-control
Impact
T1485 Data Destruction; T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery
Exfiltration
T1537 Transfer Data to Cloud Account; T1567.002 Exfiltration to Cloud Storage
Credential Access
T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle
Persistence
defense-impairment
T1553.002 Code Signing; T1685 Disable or Modify Tools; T1685.005 Clear Windows Event Logs
Resource Development
Reconnaissance
Affected products and versions in Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and
- Citrix — NetScaler ADC
- Citrix — NetScaler Gateway
- Kontron — ktapi.sys driver
Remediation for Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and
Patches
- Citrix NetScaler ADC and NetScaler Gateway 14.1 before 14.1-43.56
- Citrix NetScaler ADC and NetScaler Gateway 13.1 before 13.1-58.32
- Citrix NetScaler ADC 13.1-FIPS and NDcPP before 13.1-37.235-FIPS and NDcPP
- Citrix NetScaler ADC 12.1-FIPS before 12.1-55.328-FIPS
Immediate actions
- Patch all Citrix NetScaler ADC and NetScaler Gateway appliances to fixed versions immediately given active exploitation and CISA KEV listing
- Terminate all active ICA and PCoIP sessions after patching, per Citrix guidance, since leaked session tokens survive a version upgrade alone
- Force re-authentication and rotate session/authentication tokens on all NetScaler Gateway and AAA virtual servers
- Hunt for and remove unauthorized RMM tool installations (ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, Total Software Deployment) not matching approved IT asset inventory
- Enable driver-blocklisting (e.g., Microsoft's vulnerable driver blocklist, WDAC) to block loading of known-vulnerable drivers including ktapi.sys and other previously abused BYOVD drivers
- Audit for outbound Cloudflare Tunnel (cloudflared) binaries and unauthorized tunnel configurations
- Review VPN authentication logs for anomalous logins using valid credentials (e.g., Cisco AnyConnect) that may indicate credential theft rather than novel intrusion
Workarounds
- Where patching cannot occur immediately, restrict access to NetScaler Gateway/AAA virtual servers to trusted source IPs and enforce additional MFA layers outside the appliance
- Disable unused Gateway/AAA virtual server configurations (ICA Proxy, CVPN, RDP Proxy) to reduce exposed attack surface
Longer-term hardening
- Implement network segmentation to limit lateral movement via RDP/SMB following initial VPN/gateway compromise
- Deploy application allowlisting and driver signing enforcement to prevent BYOVD kernel-level EDR tampering
- Establish continuous monitoring for shadow-copy deletion (vssadmin delete shadows) and mass service termination targeting backup/security software (Veeam, SQL Server, BackupExec)
- Formalize an approved RMM tool allowlist and alert on any RMM tool execution outside that baseline
- Maintain immutable, offline/air-gapped backups given the presence of destructive wiper functionality in Anubis and data-destroying bugs in VECT that defeat recovery even after ransom payment
CVEs associated with Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and
Weaknesses (CWE) in Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and
CWE-20, CWE-125, CWE-287, CWE-306
Timeline of Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and
- Anubis ransomware operation emerges as a rebrand/evolution of the earlier 'Sphinx' prototype.
- Anubis formally announces its ransomware-as-a-service operation and affiliate program.
- NVD publishes initial details for CVE-2025-5777 (Citrix Bleed 2), describing an insufficient input validation vulnerability leading to memory overread in NetScaler ADC/Gateway.
- Rubrik publishes analysis of Anubis ransomware's destructive /WIPEMODE wiper feature.
- CISA adds CVE-2025-5777 to its Known Exploited Vulnerabilities (KEV) catalog, confirming active in-the-wild exploitation.
- GreyNoise records a peak in scanning/exploitation activity targeting CVE-2025-5777.
- CipherForce ransomware operation is active, claiming 6 victims prior to its rebrand.
- VECT ransomware group partners with TeamPCP for joint operations.
- CipherForce ransomware operation rebrands as TeamPCP.
- Anubis claims 11 new victims in June 2026 alone, bringing its total to 91 claimed victims across healthcare, business services, manufacturing, technology, and financial services sectors.
- The Gentlemen ransomware group is observed deploying a zero-day BYOVD exploit against the Kontron ktapi.sys driver to disable target EDR products.
- The Hacker News publishes consolidated reporting on ransomware groups (Anubis, The Gentlemen, VECT, TeamPCP) exploiting Citrix Bleed 2 and BYOVD techniques for initial access and privilege escalation.
Sources cited for Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and
- Ransomware Groups Turn to Citrix Bleed 2 and BYOVD Techniques for Initial Access
- CVE-2025-5777 Detail
- CVE-2025-5777 - Citrix Support Knowledge Base (CTX693420)
- CitrixBleed 2: Critical NetScaler Flaw Exposes Sensitive Memory Contents to Remote Attackers
- CVE-2025-5777: Citrix Bleed 2 Opens Old Wounds
- CVE-2025-5777: Citrix NetScaler Bleed 2
- CitrixBleed 2: When Memory Leaks Become Session Hijacks
- CVE-2025-5777: Citrix Bleed 2 Memory Leak Vulnerability Explained
- CVE-2025-5777 Exposes Citrix NetScaler to Dangerous Memory Leak Attacks
- June 27 Advisory: Multiple Vulnerabilities in NetScaler Gateway & ADC [CVE-2025-5777 & CVE-2025-6543 & CVE-2025-5439]
- CVE-2025-5777 (CitrixBleed 2) Exposes NetScaler Gateway Devices to Remote Exploitation
- Anubis: A Closer Look at an Emerging Ransomware with Built-in Wiper
- Wipe, leak, extort: The crazy hybrid playbook of Anubis ransomware
- Anubis Ransomware-as-a-Service Kit Adds Data Wiper
- Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets' EDRs
Threats related to Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and
- Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2 (CVE-2025-5777) Exploitation Wave
- The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS Affiliate Program
- The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework (400+ processes, 8 BYOVD variants) and 90% affiliate payouts
- Anubis Ransomware Encrypts Nutanix Systems and Exfiltrates 1TB from Coca-Cola's Fairlife Dairy Subsidiary, Halting US Production
- Q1 2026 Ransomware Landscape: Qilin Dominance, LockBit 5.0 Comeback, and FortiGate (CVE-2024-55591) / Oracle EBS (CVE-2025-61882) Mass Exploitation
- The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte): FortiGate/VPN Intrusion Chain, GentleKiller BYOVD EDR Killers, and Rclone Exfiltration
Detection coverage for TL-2026-1086
As of 2026-07-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1086 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.