Threat reportRansomwareTL-2026-3302
Anubis Ransomware Attack on Fairlife via CitrixBleed 2 (CVE-2025-5777) - Network Edge Risk
Anubis Ransomware Attack on Fairlife via CitrixBleed 2 (TL-2026-3302), also tracked as CitrixBleed 2, is a high-severity ransomware operation scored CVSS 9.3, first published 2026-10-11. It is attributed to Anubis with medium confidence, affects Citrix (Cloud Software Group) NetScaler ADC and NetScaler Gateway, references 1 CVE (CVE-2025-5777), maps to 16 MITRE ATT&CK techniques (T1003, T1021.001, T1021.002), and is covered by 9 detection rules and 21 indicators of compromise.
- CVSS
- 9.3/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 16MITRE ATT&CK
- Actors
- 1Anubis
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 21Indicators of compromise
Key facts for TL-2026-3302
- Threat ID
- TL-2026-3302
- Also known as
- CitrixBleed 2, Fairlife ransomware attack
- Severity
- HIGH
- CVSS
- 9.3
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution
- Anubis
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- food and beverage, manufacturing, health, business services, technology, financial services
- Target regions
- North America, united kingdom, australia, france, canada
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in Anubis Ransomware Attack on Fairlife via CitrixBleed 2
Malware and tooling: Anubis Ransomware, Sphinx, anubis, MeshAgent, PCHunter, PSEXEC, PuTTY, Rclone - S1040, Remotely, S3 Browser, ScreenConnect, Total Software Deployment
How Anubis Ransomware Attack on Fairlife via CitrixBleed 2 works
The Anubis ransomware-as-a-service operation exploited CitrixBleed 2 (CVE-2025-5777) in Citrix NetScaler ADC/Gateway to gain initial access to Fairlife (Coca-Cola-owned dairy company), claiming ~1 TB of stolen data and encrypting servers. Production at all four U.S. plants stopped and most resumed within 11 days; patching alone does not invalidate session tokens stolen before the fix.
CVE-2025-5777 (CitrixBleed 2) is an insufficient input validation flaw leading to a memory over-read in Citrix NetScaler ADC and NetScaler Gateway appliances configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. An unauthenticated attacker can send a deliberately malformed request and receive fragments of appliance memory, including other users' session tokens. A stolen valid session token lets the attacker impersonate an already-authenticated employee and bypass MFA without knowing the password. Citrix tracked it in advisory CTX693420, CISA added it to the Known Exploited Vulnerabilities catalog on 2025-07-10, and public sources cite a CVSS score of 9.3.
In early July 2026 an intruder entered Fairlife's production environment. Coca-Cola disclosed the incident in a 2026-07-16 SEC filing after production stopped at all four U.S. Fairlife plants (Canadian operations continued). Anubis listed Fairlife on its leak site around 2026-07-20, claimed it encrypted Fairlife servers (reporting of Nutanix systems comes from Eclypsium and secondary reporting) and stole approximately 1 TB of data, and published files on 2026-07-27 after Coca-Cola declined to negotiate and reported the incident to law enforcement. Coca-Cola confirmed data theft but did not validate all of Anubis's claims. Most U.S. production resumed within 11 days. Eclypsium's analysis (2026-08-13) stresses that patching closes the vulnerability but does not invalidate session material obtained before the patch, so a compromise assessment and session revocation are required, and that edge-device trustworthiness cannot be assumed after patching.
Anubis is a ransomware-as-a-service operation active since roughly December 2024 (reported as a rebrand of Sphinx), formally announced on the RAMP forum in February 2025, with an 80% affiliate profit share and an optional destructive /WIPEMODE module that reduces files to 0 KB irrespective of ransom payment. Reporting attributes 91 victims to the group (11 in June 2026), more than half in the U.S. Affiliates are described as hands-on-keyboard operators: after edge access via CitrixBleed 2 or purchased/stolen VPN credentials (e.g., Cisco AnyConnect), they move laterally with RDP, SMB, PsExec and Group Policy, deploy legitimate RMM tools (ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, Total Software Deployment) for persistence, use credential-dumping utilities, stage exfiltration with cloud-transfer tools (S3 Browser, rclone, s5cmd, WinSCP) and tunnel with Cloudflare Tunnel (cloudflared). Defense evasion includes disabling Windows Defender real-time protection, SophosUninstall activity, PCHunter artifacts, log clearing and encryptor deletion after execution. Hunting guidance associates the URL path /oauth/idp/logout.html with CitrixBleed 2 exploitation attempts. No file hashes, IPs or domains were published in the sources reviewed; BeaconBeagle correlation was not applicable because no network IOCs (IP/domain) were available.
MITRE ATT&CK techniques used in TL-2026-3302
Credential Access
T1003 OS Credential Dumping; T1539 Steal Web Session Cookie
Lateral Movement
T1021.001 Remote Services: Remote Desktop Protocol; T1021.002 Remote Services: SMB/Windows Admin Shares; T1550.004 Use Alternate Authentication Material: Web Session Cookie
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application
Command and Control
T1219 Remote Access Tools; T1572 Protocol Tunneling
defense-impairment
T1484.001 Domain or Tenant Policy Modification: Group Policy Modification; T1685 Disable or Modify Tools
Impact
T1485 Data Destruction; T1657 Financial Theft
Exfiltration
T1567 Exfiltration Over Web Service
Execution
Affected products and versions in Anubis Ransomware Attack on Fairlife via CitrixBleed 2
- Citrix (Cloud Software Group) — NetScaler ADC and NetScaler Gateway (configured as Gateway or AAA virtual server)
Vulnerable versions: 14.1 before 14.1-43.56; 13.1 before 13.1-58.32; 13.1-FIPS/NDcPP before 13.1-37.235; 12.1-FIPS before 12.1-55.328; 12.1 and 13.0 (end of life)
Fixed in: 14.1-43.56 and later; 13.1-58.32 and later; 13.1-37.235-FIPS/NDcPP and later; 12.1-55.328-FIPS and later
Remediation for Anubis Ransomware Attack on Fairlife via CitrixBleed 2
Patches
- Upgrade to NetScaler 14.1-43.56+, 13.1-58.32+, 13.1-37.235-FIPS/NDcPP+, 12.1-55.328-FIPS+ (12.1 and 13.0 are end-of-life; migrate)
Immediate actions
- Patch NetScaler ADC/Gateway to fixed builds per Citrix advisory CTX693420
- Terminate all active ICA/PCoIP/VPN/AAA sessions and revoke persistent session tokens after patching
- Hunt NetScaler logs for requests to /oauth/idp/logout.html and anomalous session reuse from new IPs
- Reset credentials and rotate secrets for accounts that authenticated through the appliance
Workarounds
- Limit exposure of Gateway/AAA virtual servers to required source ranges until patched and sessions are revoked
Longer-term hardening
- Perform compromise assessment of edge appliances and treat patched devices as untrusted until verified
- Restrict and monitor RMM tooling, cloudflared and cloud-transfer tools (rclone, s5cmd, S3 Browser, WinSCP)
- Isolate hypervisor/Nutanix management networks and enforce MFA on admin access
- Maintain offline, immutable backups given the destructive /WIPEMODE capability
CVEs associated with Anubis Ransomware Attack on Fairlife via CitrixBleed 2
Weaknesses (CWE) in Anubis Ransomware Attack on Fairlife via CitrixBleed 2
Timeline of Anubis Ransomware Attack on Fairlife via CitrixBleed 2
- Anubis ransomware-as-a-service activity begins (reported as a rebrand of Sphinx); month approximate per reporting of 'late 2024 / December 2024'.
- Anubis formally announces its affiliate program on the RAMP forum (month approximate), offering an 80% affiliate share.
- CVE-2025-5777 (CitrixBleed 2) disclosed by Citrix in advisory CTX693420 and tracked by national CERTs such as NCSC Ireland.
- CISA adds CVE-2025-5777 to the Known Exploited Vulnerabilities catalog, confirming in-the-wild exploitation.
- Intruder enters Fairlife production systems in early July 2026 via CitrixBleed 2 session theft; precise date not published, month-start used as placeholder for 'early July'.
- Coca-Cola discloses the incident in an SEC filing after production stops at all four U.S. Fairlife plants.
- Anubis lists Fairlife on its leak site, claiming ~1 TB of exfiltrated data and encrypted servers, with a one-week deadline.
- Cybersecurity Dive reports the Anubis claim; Fairlife says there is no impact on product safety or quality.
- Anubis publishes stolen files after Coca-Cola refuses to negotiate and reports the incident to law enforcement.
- Eclypsium publishes analysis noting most U.S. production resumed within 11 days and that patching does not revoke previously stolen session tokens.
Sources cited for Anubis Ransomware Attack on Fairlife via CitrixBleed 2
- When Patching Isn't Enough: What the Fairlife Ransomware Attack Says About Network Edge Risk
- Threat group claims ransomware attack on Coca-Cola's dairy unit Fairlife (Cybersecurity Dive)
- Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials (The Hacker News)
- Fairlife ransomware (Adaptive Security)
- Citrix Bleed 2 Powers Anubis Ransomware Intrusions (SecPod)
- Anubis ransomware exploits CitrixBleed 2 and RMM tools (Techzine)
- NCSC Ireland advisory: CVE-2025-5777 (Citrix NetScaler)
- CISA adds Citrix NetScaler ADC and Gateway flaw to KEV catalog (Security Affairs)
- CVE-2025-5777 Citrix NetScaler Out-of-Bounds Memory Read (Ridge Security)
Detection coverage for TL-2026-3302
As of 2026-10-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3302 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.