ransomware
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
High
Summary
The Anubis ransomware group, a rebranded version of Sphinx, is actively exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to gain initial access to victim networks. They leverage legitimate RMM tools like ScreenConnect and Zoho Assist, combined with stolen VPN credentials and techniques like credential stuffing, to move laterally and deploy ransomware. The group’s tactics include disabling security software and employing a Go-based backdoor dubbed ‘The Gentlemen’ to further their operations, targeting sectors including healthcare, business services, and finance.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
