Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and Kontron Driver BYOVD for Access and Privilege Escalation — Threadlinqs Intelligence
As of 2026-07-02, Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and Kontron Driver BYOVD for Access and Privilege Escalation is a critical-severity ransomware threat attributed to Anubis, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 28 indicators of compromise.
Threat ID: TL-2026-1086 · Severity: CRITICAL · CVSS: 9.3 · Status: ACTIVE · Category: RANSOMWARE
Attribution: Anubis · FINANCIAL
Multiple ransomware-as-a-service operations, including Anubis, The Gentlemen, VECT, and TeamPCP (formerly CipherForce), are actively exploiting the Citrix Bleed 2 authentication bypass/memory-overread
Since June 2026, threat intelligence has confirmed active exploitation of CVE-2025-5777 ("Citrix Bleed 2"), a critical insufficient-input-validation vulnerability in Citrix NetScaler ADC and Gateway that produces a memory overread, allowing unauthenticated remote attackers to leak session tokens and other sensitive memory contents from vulnerable appliances. Leaked session tokens allow attackers to hijack authenticated sessions and bypass multi-factor authentication entirely, echoing the original 2023 CitrixBleed (CVE-2023-4966) flaw. CISA added CVE-2025-5777 to its Known Exploited Vulnerabilities (KEV) catalog on July 10, 2025, confirming in-the-wild exploitation; GreyNoise recorded a scanning/exploitation spike peaking around July 11, 2025 that has continued into 2026 as ransomware affiliates weaponize the flaw for initial access against internet-facing NetScaler Gateway/AAA virtual servers.
Anubis, a ransomware-as-a-service operation that emerged in late 2024 as a rebrand of the "Sphinx" prototype and formally launched in February 2025, has claimed 91 victims to date (11 in June 2026 alone), with over 50% of victims based in the United States and additional victims in the UK, Australia, France, and Canada, spanning healthcare, business services, manufacturing, technology, and financial services. Anubis is notable for an integrated destructive wiper capability (/WIPEMODE) that reduces files to 0 KB regardless of whether the ransom is paid, removing any recovery incentive even for paying victims. Anubis offers affiliates flexible monetization: an 80% payout RaaS model, a 40% cut extortion-assist model, and a 50% cut post-compromise extortion model.
The Gentlemen, first observed in mid-2025, has escalated its EDR-evasion tradecraft by deploying a zero-day BYOVD exploit against the Kontron ktapi.sys driver (previously undocumented as attacker tooling) to gain kernel-level access and disable EDR/antivirus protections, in addition to prior use of other vulnerable drivers (ProcessMonitorDriver.sys, wamsdk.sys, gamedriverx64.sys, biontdrv.sys, inpoutx64.sys, wsftprm.sys) as part of an EDR-killer framework capable of disabling 400+ security processes.
VECT, a newer ransomware strain, partnered with TeamPCP (the May 2026 rebrand of the CipherForce ransomware operation, which had claimed 6 victims as of February 2026) in March 2026. VECT's encryption implementation contains a flaw that permanently destroys files larger than 128KB, making recovery impossible even with a valid decryptor.
Across these campaigns, common post-exploitation TTPs include: abuse of valid VPN credentials (e.g., Cisco AnyConnect) for initial access alongside NetScaler exploitation; RDP/SMB-based lateral movement; PsExec for remote service creation; disabling of Windows Defender and uninstalling Sophos endpoint protection; clearing of Windows event logs; use of Cloudflare Tunnel (cloudflared) for covert network tunneling and C2; a Go-based backdoor with SOCKS proxy capability; and data exfiltration via S3 Browser, rclone, s5cmd, WinSCP, and PuTTY. Persistence is frequently established through abuse of legitimate remote monitoring and management (RMM) tools including ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, and Total Software Deployment, allowing attackers to blend into normal administrative traffic.
Weaknesses (CWE)
CWE-20, CWE-125, CWE-287, CWE-306
Target sectors: health, business services, manufacturing, technology, financial services, critical infrastructure
Target regions: united states of america, united kingdom, australia, france, canada
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 28 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, CRITICAL, threat intelligence, cybersecurity, CVE-2025-5777, T1190, T1078, T1133, T1539, T1557, T1047, T1569.002, T1219, T1543.003, T1068