CVE Tools

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

The Hacker NewsBy The Hacker News

Reported exploitednetscaleranubiscloudflared

Our summary

Threat actors linked to the Anubis ransomware operation have been seen abusing Citrix Bleed 2 to gain initial access, specifically via CVE-2025-5777 affecting Citrix NetScaler ADC and Gateway (CVSS 9.3). The same reporting highlights their use of remote access tools, credential theft, RDP/PsExec for lateral movement, and follow-on data theft before deploying ransomware.
In related ransomware activity, Kaspersky described The Gentlemen RaaS using a Go-based backdoor and weaponizing a BYOVD scenario involving the ktapi.sys driver for kernel-level abuse, while Sophos reported a VECT and TeamPCP supply-chain partnership that enables ransomware deployment across victims of Trivy and LiteLLM supply chain attacks. These developments matter because they combine high-impact exploitation and credential compromise with scalable “industrialized” deployment tactics that lower the barrier for attackers.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store