CitrixBleed 2 (CVE-2025-5777) Weaponized by Initial Access Broker for DragonForce Ransomware Deployment — Threadlinqs Intelligence
As of 2026-07-10, CitrixBleed 2 (CVE-2025-5777) Weaponized by Initial Access Broker for DragonForce Ransomware Deployment is a critical-severity vulnerability threat attributed to DragonForce-affiliated Initial Access Broker, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 43 indicators of compromise.
Threat ID: TL-2026-1150 · Severity: CRITICAL · CVSS: 9.3 · Status: ACTIVE · Category: VULNERABILITY
Updated: 2026-07-10 · revalidated 1× · latest source
Attribution: DragonForce-affiliated Initial Access Broker · FINANCIAL
An initial access broker, possibly affiliated with the DragonForce ransomware cartel, is exploiting the CitrixBleed 2 pre-authentication memory-overread vulnerability (CVE-2025-5777) in Citrix
Huntress documented a consistent seven-step attack chain across at least six intrusions between January and June 2026, with the fastest observed compromise-to-encryption time under one hour. The operation begins with exploitation of CVE-2025-5777 ("CitrixBleed 2"), an out-of-bounds read vulnerability (CWE-125, combined with CWE-908 use of uninitialized resource and CWE-457 use of uninitialized variable) in Citrix NetScaler ADC and Gateway appliances configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. The attacker sends malformed POST requests to the /p/u/doAuthentication.do pre-authentication login endpoint with an empty login parameter; the appliance fails to validate the missing input and reflects an uninitialized stack buffer inside an <InitialValue> XML element of the response, leaking roughly 127 bytes of adjacent heap memory per request. By repeatedly polling the endpoint the attacker harvests valid NSC_AAAC session cookies belonging to already-authenticated VPN users, which are then replayed to hijack sessions and bypass multi-factor authentication entirely, since MFA is never re-prompted for an already-valid session token. Vulnerable versions are NetScaler ADC/Gateway 14.1 before 14.1-43.56, 13.1 before 13.1-58.32, 13.1-FIPS/NDcPP before 13.1-37.235-FIPS/NDcPP, and 12.1-FIPS before 12.1-55.328-FIPS. The bug was disclosed by Citrix on 2025-06-17, scope-expanded and patched by 2025-06-23, and added to the CISA KEV catalog on 2025-07-10 after GreyNoise observed exploitation attempts beginning 2025-06-23 — nearly two weeks before public PoC release. It is functionally and thematically related to the original CitrixBleed (CVE-2023-4966) and has separately been linked to Cl0p ransomware activity. Huntress explicitly ruled out CVE-2026-4368 (a NetScaler session-management time-of-check/time-of-use flaw) as the vector in these specific intrusions.
Once inside the internal network with a hijacked session, the operator pivots to a Windows privilege-escalation technique abusing REG_LINK symbolic link values. A symbolic link is created under the RdpBus device-class GUID pointing at the Group Policy state hierarchy (...\\Group Policy State\\Machine\\GPO-List\ est). Running gpupdate triggers a policy refresh in the SYSTEM context; because the registry write follows the attacker-controlled symlink, the refresh redirects SYSTEM-context writes into protected service configuration keys, specifically hijacking the AppMgmt (Application Management) service's configuration. The attacker then issues "cmd.exe /c sc start AppMgmt >nul 2>nul", causing the Service Control Manager to launch the hijacked AppMgmt configuration as SYSTEM. The hijacked service executes "net user <account> <password> /add /y" to create a backdoor local administrator account (observed names: ctxsvc, CtxAppVCOMService, test), after which the operator restores the original registry state to reduce forensic visibility.
With a SYSTEM-level backdoor account established, the operator installs commodity remote-access tooling for durable persistence and hands-on-keyboard access, deploying ScreenConnect (via installers named us.msi, SC.msi, 1111.msi) and Zoho Assist (za.msi), staged through archives fetched from the temp.sh anonymous file-sharing service (asas.zip, ex.zip, and files matching *_update.zip, protected with the password "loko123"). ScreenConnect relay traffic was observed terminating at relay.dltsolutions[.]top, relay.eurofin[.]digital:8041, and vpts[.]us, using ScreenConnect instance IDs 9963f404a99f0fc4 and aee74a66ea5bb239; a Netbird-based relay was also observed at opa[.]tlsd[.]shop. Privilege-escalation dropper binaries were named eng.exe, legal.exe, exsym.exe, as.exe, and exp6.exe.
From the persistent foothold the operator performs credential dumping (consistent with Mimikatz-style OS credential access), host and domain enumeration, and lateral movement toward domain controllers using tooling consistent with Impa
Weaknesses (CWE)
CWE-125, CWE-908, CWE-457, CWE-287, CWE-20
Target sectors: technology, professional services, retail, finance, health, government administration
Target regions: North America, Europe, united kingdom
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 43 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2025-5777, T1190, T1539, T1111, T1212, T1548, T1068, T1136, T1112, T1505, T1047