news.mlab.sh
Back to the feed
ransomware

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

High
Image: The Hacker News
Summary

The Anubis ransomware group, a rebranded version of Sphinx, is actively exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to gain initial access to victim networks. They leverage legitimate RMM tools like ScreenConnect and Zoho Assist, combined with stolen VPN credentials and techniques like credential stuffing, to move laterally and deploy ransomware. The group’s tactics include disabling security software and employing a Go-based backdoor dubbed ‘The Gentlemen’ to further their operations, targeting sectors including healthcare, business services, and finance.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.