Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and Kontron Driver BYOVD for Access and Privilege Escalation

Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and (TL-2026-1086), also tracked as Citrix Bleed 2, is a critical-severity ransomware operation scored CVSS 9.3, first published 2026-07-02. It is attributed to Anubis with medium confidence, affects Citrix NetScaler ADC, references 1 CVE (CVE-2025-5777), maps to 31 MITRE ATT&CK techniques (T1005, T1016, T1018), and is covered by 9 detection rules and 28 indicators of compromise.

Key facts for TL-2026-1086

Threat ID
TL-2026-1086
Also known as
Citrix Bleed 2, CitrixBleed 2
Severity
CRITICAL
CVSS
9.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N)
Status
ACTIVE
Category
RANSOMWARE
First published
2026-07-02
Last reviewed
2026-07-02
Attribution
Anubis
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
health, business services, manufacturing, technology, financial services, critical infrastructure
Target regions
united states of america, united kingdom, australia, france, canada
Detection rules
9
Indicators of compromise
28

Malware and tooling in Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and

Malware and tooling: TeamPCP, anubis, the gentlemen, vect, MeshAgent, PuTTY, Rclone - S1040, Remotely, S3 Browser, ScreenConnect, Total Software Deployment, UltraVNC

Multiple ransomware-as-a-service operations, including Anubis, The Gentlemen, VECT, and TeamPCP (formerly CipherForce), are actively exploiting the Citrix Bleed 2 authentication bypass/memory-overread flaw (CVE-2025-5777, CVSS 9.3) in NetScaler ADC/Gateway for initial access, alongside a Bring Your Own Vulnerable Driver (BYOVD) technique abusing the Kontron ktapi.sys driver to blind EDR, and abuse of legitimate RMM tools (ScreenConnect, Zoho Assist, MeshAgent) for persistence.

How Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and works

Since June 2026, threat intelligence has confirmed active exploitation of CVE-2025-5777 ("Citrix Bleed 2"), a critical insufficient-input-validation vulnerability in Citrix NetScaler ADC and Gateway that produces a memory overread, allowing unauthenticated remote attackers to leak session tokens and other sensitive memory contents from vulnerable appliances. Leaked session tokens allow attackers to hijack authenticated sessions and bypass multi-factor authentication entirely, echoing the original 2023 CitrixBleed (CVE-2023-4966) flaw. CISA added CVE-2025-5777 to its Known Exploited Vulnerabilities (KEV) catalog on July 10, 2025, confirming in-the-wild exploitation; GreyNoise recorded a scanning/exploitation spike peaking around July 11, 2025 that has continued into 2026 as ransomware affiliates weaponize the flaw for initial access against internet-facing NetScaler Gateway/AAA virtual servers.

Anubis, a ransomware-as-a-service operation that emerged in late 2024 as a rebrand of the "Sphinx" prototype and formally launched in February 2025, has claimed 91 victims to date (11 in June 2026 alone), with over 50% of victims based in the United States and additional victims in the UK, Australia, France, and Canada, spanning healthcare, business services, manufacturing, technology, and financial services. Anubis is notable for an integrated destructive wiper capability (/WIPEMODE) that reduces files to 0 KB regardless of whether the ransom is paid, removing any recovery incentive even for paying victims. Anubis offers affiliates flexible monetization: an 80% payout RaaS model, a 40% cut extortion-assist model, and a 50% cut post-compromise extortion model.

The Gentlemen, first observed in mid-2025, has escalated its EDR-evasion tradecraft by deploying a zero-day BYOVD exploit against the Kontron ktapi.sys driver (previously undocumented as attacker tooling) to gain kernel-level access and disable EDR/antivirus protections, in addition to prior use of other vulnerable drivers (ProcessMonitorDriver.sys, wamsdk.sys, gamedriverx64.sys, biontdrv.sys, inpoutx64.sys, wsftprm.sys) as part of an EDR-killer framework capable of disabling 400+ security processes.

VECT, a newer ransomware strain, partnered with TeamPCP (the May 2026 rebrand of the CipherForce ransomware operation, which had claimed 6 victims as of February 2026) in March 2026. VECT's encryption implementation contains a flaw that permanently destroys files larger than 128KB, making recovery impossible even with a valid decryptor.

Across these campaigns, common post-exploitation TTPs include: abuse of valid VPN credentials (e.g., Cisco AnyConnect) for initial access alongside NetScaler exploitation; RDP/SMB-based lateral movement; PsExec for remote service creation; disabling of Windows Defender and uninstalling Sophos endpoint protection; clearing of Windows event logs; use of Cloudflare Tunnel (cloudflared) for covert network tunneling and C2; a Go-based backdoor with SOCKS proxy capability; and data exfiltration via S3 Browser, rclone, s5cmd, WinSCP, and PuTTY. Persistence is frequently established through abuse of legitimate remote monitoring and management (RMM) tools including ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, and Total Software Deployment, allowing attackers to blend into normal administrative traffic.

MITRE ATT&CK techniques used in TL-2026-1086

Collection

T1005 Data from Local System

Discovery

T1016 System Network Configuration Discovery; T1018 Remote System Discovery

Lateral Movement

T1021.001 Remote Desktop Protocol; T1021.002 SMB/Windows Admin Shares

Execution

T1047 Windows Management Instrumentation; T1569.002 Service Execution

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application

Command and Control

T1090 Proxy; T1105 Ingress Tool Transfer; T1572 Protocol Tunneling

Defense Evasion

T1140 Deobfuscate/Decode Files or Information; T1211 Exploitation for Stealth

command-and-control

T1219 Remote Access Tools

Impact

T1485 Data Destruction; T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery

Exfiltration

T1537 Transfer Data to Cloud Account; T1567.002 Exfiltration to Cloud Storage

Credential Access

T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle

Persistence

T1543.003 Windows Service

defense-impairment

T1553.002 Code Signing; T1685 Disable or Modify Tools; T1685.005 Clear Windows Event Logs

Resource Development

T1588.005 Exploits

Reconnaissance

T1595.002 Vulnerability Scanning

Affected products and versions in Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and

  • Citrix — NetScaler ADC
  • Citrix — NetScaler Gateway
  • Kontron — ktapi.sys driver

Remediation for Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and

Patches

  • Citrix NetScaler ADC and NetScaler Gateway 14.1 before 14.1-43.56
  • Citrix NetScaler ADC and NetScaler Gateway 13.1 before 13.1-58.32
  • Citrix NetScaler ADC 13.1-FIPS and NDcPP before 13.1-37.235-FIPS and NDcPP
  • Citrix NetScaler ADC 12.1-FIPS before 12.1-55.328-FIPS

Immediate actions

  • Patch all Citrix NetScaler ADC and NetScaler Gateway appliances to fixed versions immediately given active exploitation and CISA KEV listing
  • Terminate all active ICA and PCoIP sessions after patching, per Citrix guidance, since leaked session tokens survive a version upgrade alone
  • Force re-authentication and rotate session/authentication tokens on all NetScaler Gateway and AAA virtual servers
  • Hunt for and remove unauthorized RMM tool installations (ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, Total Software Deployment) not matching approved IT asset inventory
  • Enable driver-blocklisting (e.g., Microsoft's vulnerable driver blocklist, WDAC) to block loading of known-vulnerable drivers including ktapi.sys and other previously abused BYOVD drivers
  • Audit for outbound Cloudflare Tunnel (cloudflared) binaries and unauthorized tunnel configurations
  • Review VPN authentication logs for anomalous logins using valid credentials (e.g., Cisco AnyConnect) that may indicate credential theft rather than novel intrusion

Workarounds

  • Where patching cannot occur immediately, restrict access to NetScaler Gateway/AAA virtual servers to trusted source IPs and enforce additional MFA layers outside the appliance
  • Disable unused Gateway/AAA virtual server configurations (ICA Proxy, CVPN, RDP Proxy) to reduce exposed attack surface

Longer-term hardening

  • Implement network segmentation to limit lateral movement via RDP/SMB following initial VPN/gateway compromise
  • Deploy application allowlisting and driver signing enforcement to prevent BYOVD kernel-level EDR tampering
  • Establish continuous monitoring for shadow-copy deletion (vssadmin delete shadows) and mass service termination targeting backup/security software (Veeam, SQL Server, BackupExec)
  • Formalize an approved RMM tool allowlist and alert on any RMM tool execution outside that baseline
  • Maintain immutable, offline/air-gapped backups given the presence of destructive wiper functionality in Anubis and data-destroying bugs in VECT that defeat recovery even after ransom payment

CVEs associated with Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and

CVE-2025-5777

Weaknesses (CWE) in Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and

CWE-20, CWE-125, CWE-287, CWE-306

Timeline of Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and

  • Anubis ransomware operation emerges as a rebrand/evolution of the earlier 'Sphinx' prototype.
  • Anubis formally announces its ransomware-as-a-service operation and affiliate program.
  • NVD publishes initial details for CVE-2025-5777 (Citrix Bleed 2), describing an insufficient input validation vulnerability leading to memory overread in NetScaler ADC/Gateway.
  • Rubrik publishes analysis of Anubis ransomware's destructive /WIPEMODE wiper feature.
  • CISA adds CVE-2025-5777 to its Known Exploited Vulnerabilities (KEV) catalog, confirming active in-the-wild exploitation.
  • GreyNoise records a peak in scanning/exploitation activity targeting CVE-2025-5777.
  • CipherForce ransomware operation is active, claiming 6 victims prior to its rebrand.
  • VECT ransomware group partners with TeamPCP for joint operations.
  • CipherForce ransomware operation rebrands as TeamPCP.
  • Anubis claims 11 new victims in June 2026 alone, bringing its total to 91 claimed victims across healthcare, business services, manufacturing, technology, and financial services sectors.
  • The Gentlemen ransomware group is observed deploying a zero-day BYOVD exploit against the Kontron ktapi.sys driver to disable target EDR products.
  • The Hacker News publishes consolidated reporting on ransomware groups (Anubis, The Gentlemen, VECT, TeamPCP) exploiting Citrix Bleed 2 and BYOVD techniques for initial access and privilege escalation.

Sources cited for Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and

Threats related to Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and

Detection coverage for TL-2026-1086

As of 2026-07-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1086 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats