Threat reportRansomwareTL-2026-3302

Anubis Ransomware Attack on Fairlife via CitrixBleed 2 (CVE-2025-5777) - Network Edge Risk

highACTIVE

Anubis Ransomware Attack on Fairlife via CitrixBleed 2 (TL-2026-3302), also tracked as CitrixBleed 2, is a high-severity ransomware operation scored CVSS 9.3, first published 2026-10-11. It is attributed to Anubis with medium confidence, affects Citrix (Cloud Software Group) NetScaler ADC and NetScaler Gateway, references 1 CVE (CVE-2025-5777), maps to 16 MITRE ATT&CK techniques (T1003, T1021.001, T1021.002), and is covered by 9 detection rules and 21 indicators of compromise.

CVSS
9.3/10High
CVEs
1Referenced vulnerabilities
Techniques
16MITRE ATT&CK
Actors
1Anubis
Detection rules
9SPL · KQL · Sigma
IOCs
21Indicators of compromise

Key facts for TL-2026-3302

Threat ID
TL-2026-3302
Also known as
CitrixBleed 2, Fairlife ransomware attack
Severity
HIGH
CVSS
9.3
Status
ACTIVE
Category
RANSOMWARE
First published
Last reviewed
Attribution
Anubis
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
food and beverage, manufacturing, health, business services, technology, financial services
Target regions
North America, united kingdom, australia, france, canada
Detection rules
9
Indicators of compromise
21

Malware and tooling in Anubis Ransomware Attack on Fairlife via CitrixBleed 2

Malware and tooling: Anubis Ransomware, Sphinx, anubis, MeshAgent, PCHunter, PSEXEC, PuTTY, Rclone - S1040, Remotely, S3 Browser, ScreenConnect, Total Software Deployment

How Anubis Ransomware Attack on Fairlife via CitrixBleed 2 works

The Anubis ransomware-as-a-service operation exploited CitrixBleed 2 (CVE-2025-5777) in Citrix NetScaler ADC/Gateway to gain initial access to Fairlife (Coca-Cola-owned dairy company), claiming ~1 TB of stolen data and encrypting servers. Production at all four U.S. plants stopped and most resumed within 11 days; patching alone does not invalidate session tokens stolen before the fix.

CVE-2025-5777 (CitrixBleed 2) is an insufficient input validation flaw leading to a memory over-read in Citrix NetScaler ADC and NetScaler Gateway appliances configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. An unauthenticated attacker can send a deliberately malformed request and receive fragments of appliance memory, including other users' session tokens. A stolen valid session token lets the attacker impersonate an already-authenticated employee and bypass MFA without knowing the password. Citrix tracked it in advisory CTX693420, CISA added it to the Known Exploited Vulnerabilities catalog on 2025-07-10, and public sources cite a CVSS score of 9.3.

In early July 2026 an intruder entered Fairlife's production environment. Coca-Cola disclosed the incident in a 2026-07-16 SEC filing after production stopped at all four U.S. Fairlife plants (Canadian operations continued). Anubis listed Fairlife on its leak site around 2026-07-20, claimed it encrypted Fairlife servers (reporting of Nutanix systems comes from Eclypsium and secondary reporting) and stole approximately 1 TB of data, and published files on 2026-07-27 after Coca-Cola declined to negotiate and reported the incident to law enforcement. Coca-Cola confirmed data theft but did not validate all of Anubis's claims. Most U.S. production resumed within 11 days. Eclypsium's analysis (2026-08-13) stresses that patching closes the vulnerability but does not invalidate session material obtained before the patch, so a compromise assessment and session revocation are required, and that edge-device trustworthiness cannot be assumed after patching.

Anubis is a ransomware-as-a-service operation active since roughly December 2024 (reported as a rebrand of Sphinx), formally announced on the RAMP forum in February 2025, with an 80% affiliate profit share and an optional destructive /WIPEMODE module that reduces files to 0 KB irrespective of ransom payment. Reporting attributes 91 victims to the group (11 in June 2026), more than half in the U.S. Affiliates are described as hands-on-keyboard operators: after edge access via CitrixBleed 2 or purchased/stolen VPN credentials (e.g., Cisco AnyConnect), they move laterally with RDP, SMB, PsExec and Group Policy, deploy legitimate RMM tools (ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, Total Software Deployment) for persistence, use credential-dumping utilities, stage exfiltration with cloud-transfer tools (S3 Browser, rclone, s5cmd, WinSCP) and tunnel with Cloudflare Tunnel (cloudflared). Defense evasion includes disabling Windows Defender real-time protection, SophosUninstall activity, PCHunter artifacts, log clearing and encryptor deletion after execution. Hunting guidance associates the URL path /oauth/idp/logout.html with CitrixBleed 2 exploitation attempts. No file hashes, IPs or domains were published in the sources reviewed; BeaconBeagle correlation was not applicable because no network IOCs (IP/domain) were available.

MITRE ATT&CK techniques used in TL-2026-3302

Credential Access

T1003 OS Credential Dumping; T1539 Steal Web Session Cookie

Lateral Movement

T1021.001 Remote Services: Remote Desktop Protocol; T1021.002 Remote Services: SMB/Windows Admin Shares; T1550.004 Use Alternate Authentication Material: Web Session Cookie

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application

Command and Control

T1219 Remote Access Tools; T1572 Protocol Tunneling

defense-impairment

T1484.001 Domain or Tenant Policy Modification: Group Policy Modification; T1685 Disable or Modify Tools

Impact

T1485 Data Destruction; T1657 Financial Theft

Exfiltration

T1567 Exfiltration Over Web Service

Execution

T1569.002 System Services: Service Execution

Affected products and versions in Anubis Ransomware Attack on Fairlife via CitrixBleed 2

  • Citrix (Cloud Software Group) — NetScaler ADC and NetScaler Gateway (configured as Gateway or AAA virtual server)
    Vulnerable versions: 14.1 before 14.1-43.56; 13.1 before 13.1-58.32; 13.1-FIPS/NDcPP before 13.1-37.235; 12.1-FIPS before 12.1-55.328; 12.1 and 13.0 (end of life)
    Fixed in: 14.1-43.56 and later; 13.1-58.32 and later; 13.1-37.235-FIPS/NDcPP and later; 12.1-55.328-FIPS and later

Remediation for Anubis Ransomware Attack on Fairlife via CitrixBleed 2

Patches

  • Upgrade to NetScaler 14.1-43.56+, 13.1-58.32+, 13.1-37.235-FIPS/NDcPP+, 12.1-55.328-FIPS+ (12.1 and 13.0 are end-of-life; migrate)

Immediate actions

  • Patch NetScaler ADC/Gateway to fixed builds per Citrix advisory CTX693420
  • Terminate all active ICA/PCoIP/VPN/AAA sessions and revoke persistent session tokens after patching
  • Hunt NetScaler logs for requests to /oauth/idp/logout.html and anomalous session reuse from new IPs
  • Reset credentials and rotate secrets for accounts that authenticated through the appliance

Workarounds

  • Limit exposure of Gateway/AAA virtual servers to required source ranges until patched and sessions are revoked

Longer-term hardening

  • Perform compromise assessment of edge appliances and treat patched devices as untrusted until verified
  • Restrict and monitor RMM tooling, cloudflared and cloud-transfer tools (rclone, s5cmd, S3 Browser, WinSCP)
  • Isolate hypervisor/Nutanix management networks and enforce MFA on admin access
  • Maintain offline, immutable backups given the destructive /WIPEMODE capability

CVEs associated with Anubis Ransomware Attack on Fairlife via CitrixBleed 2

CVE-2025-5777

Weaknesses (CWE) in Anubis Ransomware Attack on Fairlife via CitrixBleed 2

CWE-125

Timeline of Anubis Ransomware Attack on Fairlife via CitrixBleed 2

  • Anubis ransomware-as-a-service activity begins (reported as a rebrand of Sphinx); month approximate per reporting of 'late 2024 / December 2024'.
  • Anubis formally announces its affiliate program on the RAMP forum (month approximate), offering an 80% affiliate share.
  • CVE-2025-5777 (CitrixBleed 2) disclosed by Citrix in advisory CTX693420 and tracked by national CERTs such as NCSC Ireland.
  • CISA adds CVE-2025-5777 to the Known Exploited Vulnerabilities catalog, confirming in-the-wild exploitation.
  • Intruder enters Fairlife production systems in early July 2026 via CitrixBleed 2 session theft; precise date not published, month-start used as placeholder for 'early July'.
  • Coca-Cola discloses the incident in an SEC filing after production stops at all four U.S. Fairlife plants.
  • Anubis lists Fairlife on its leak site, claiming ~1 TB of exfiltrated data and encrypted servers, with a one-week deadline.
  • Cybersecurity Dive reports the Anubis claim; Fairlife says there is no impact on product safety or quality.
  • Anubis publishes stolen files after Coca-Cola refuses to negotiate and reports the incident to law enforcement.
  • Eclypsium publishes analysis noting most U.S. production resumed within 11 days and that patching does not revoke previously stolen session tokens.

Sources cited for Anubis Ransomware Attack on Fairlife via CitrixBleed 2

Detection coverage for TL-2026-3302

As of 2026-10-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3302 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
21 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats