# Anubis Ransomware Attack on Fairlife via CitrixBleed 2 (CVE-2025-5777) - Network Edge Risk

> The Anubis ransomware-as-a-service operation exploited CitrixBleed 2 (CVE-2025-5777) in Citrix NetScaler ADC/Gateway to gain initial access to Fairlife (Coca-Cola-owned dairy company), claiming ~1 TB of stolen data and encrypting servers. Production at all four U.S. plants stopped and most resumed within 11 days; patching alone does not invalidate session tokens stolen before the fix.

- **Published:** 2026-10-11T13:09:32Z
- **Last reviewed:** 2026-10-11T13:09:32Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3302
- **ID:** TL-2026-3302
- **Severity:** HIGH (CVSS 9.3)
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Actor:** Anubis
- **Detections:** 9 · **IOCs:** 21 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-5777

## Description

CVE-2025-5777 (CitrixBleed 2) is an insufficient input validation flaw leading to a memory over-read in Citrix NetScaler ADC and NetScaler Gateway appliances configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. An unauthenticated attacker can send a deliberately malformed request and receive fragments of appliance memory, including other users' session tokens. A stolen valid session token lets the attacker impersonate an already-authenticated employee and bypass MFA without knowing the password. Citrix tracked it in advisory CTX693420, CISA added it to the Known Exploited Vulnerabilities catalog on 2025-07-10, and public sources cite a CVSS score of 9.3.

In early July 2026 an intruder entered Fairlife's production environment. Coca-Cola disclosed the incident in a 2026-07-16 SEC filing after production stopped at all four U.S. Fairlife plants (Canadian operations continued). Anubis listed Fairlife on its leak site around 2026-07-20, claimed it encrypted Fairlife servers (reporting of Nutanix systems comes from Eclypsium and secondary reporting) and stole approximately 1 TB of data, and published files on 2026-07-27 after Coca-Cola declined to negotiate and reported the incident to law enforcement. Coca-Cola confirmed data theft but did not validate all of Anubis's claims. Most U.S. production resumed within 11 days. Eclypsium's analysis (2026-08-13) stresses that patching closes the vulnerability but does not invalidate session material obtained before the patch, so a compromise assessment and session revocation are required, and that edge-device trustworthiness cannot be assumed after patching.

Anubis is a ransomware-as-a-service operation active since roughly December 2024 (reported as a rebrand of Sphinx), formally announced on the RAMP forum in February 2025, with an 80% affiliate profit share and an optional destructive /WIPEMODE module that reduces files to 0 KB irrespective of ransom payment. Reporting attributes 91 victims to the group (11 in June 2026), more than half in the U.S. Affiliates are described as hands-on-keyboard operators: after edge access via CitrixBleed 2 or purchased/stolen VPN credentials (e.g., Cisco AnyConnect), they move laterally with RDP, SMB, PsExec and Group Policy, deploy legitimate RMM tools (ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, Total Software Deployment) for persistence, use credential-dumping utilities, stage exfiltration with cloud-transfer tools (S3 Browser, rclone, s5cmd, WinSCP) and tunnel with Cloudflare Tunnel (cloudflared). Defense evasion includes disabling Windows Defender real-time protection, SophosUninstall activity, PCHunter artifacts, log clearing and encryptor deletion after execution. Hunting guidance associates the URL path /oauth/idp/logout.html with CitrixBleed 2 exploitation attempts. No file hashes, IPs or domains were published in the sources reviewed; BeaconBeagle correlation was not applicable because no network IOCs (IP/domain) were available.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1133 External Remote Services
- T1539 Steal Web Session Cookie
- T1003 OS Credential Dumping
- T1550.004 Use Alternate Authentication Material: Web Session Cookie
- T1021.001 Remote Services: Remote Desktop Protocol
- T1021.002 Remote Services: SMB/Windows Admin Shares
- T1569.002 System Services: Service Execution
- T1219 Remote Access Tools
- T1572 Protocol Tunneling
- T1685 Disable or Modify Tools
- T1484.001 Domain or Tenant Policy Modification: Group Policy Modification
- T1567 Exfiltration Over Web Service
- T1485 Data Destruction
- T1657 Financial Theft

## Sources

- [When Patching Isn't Enough: What the Fairlife Ransomware Attack Says About Network Edge Risk](https://eclypsium.com/blog/fairlife-ransomware-citrixbleed-network-edge-risk/)
- [Threat group claims ransomware attack on Coca-Cola's dairy unit Fairlife (Cybersecurity Dive)](https://www.cybersecuritydive.com/news/threat-group-ransomware-coca-colas-dairy-Fairlife/825900/)
- [Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials (The Hacker News)](https://thehackernews.com/2026/07/ransomware-groups-turn-to-citrix-bleed.html)
- [Fairlife ransomware (Adaptive Security)](https://www.adaptivesecurity.com/blog/fairlife-ransomware)
- [Citrix Bleed 2 Powers Anubis Ransomware Intrusions (SecPod)](https://www.secpod.com/learn/security-research/citrix-bleed-2-powers-anubis-ransomware-intrusions)
- [Anubis ransomware exploits CitrixBleed 2 and RMM tools (Techzine)](https://www.techzine.eu/news/security/142624/anubis-ransomware-exploits-citrixbleed-2-and-rmm-tools)
- [NCSC Ireland advisory: CVE-2025-5777 (Citrix NetScaler)](https://ncsc.gov.ie/pdfs/2506190185_CVE-2025-5777.pdf)
- [CISA adds Citrix NetScaler ADC and Gateway flaw to KEV catalog (Security Affairs)](https://securityaffairs.com/?p=179813)
- [CVE-2025-5777 Citrix NetScaler Out-of-Bounds Memory Read (Ridge Security)](https://ridgesecurity.ai/blog/citrix-netscaler-out-of-bounds-memory-read-vulnerability-cve-2025-5777/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3302
