← Back to Daily Briefing

The Anubis Ransomware group is executing high-velocity exploitation of CVE-2025-5777, a critical vulnerability in Citrix NetScaler ADC/Gateway appliances, colloquially known as "Citrix Bleed 2." This vulnerability permits session token and memory disclosure, allowing attackers to bypass authentication and hijack active sessions. By targeting edge-facing infrastructure, Anubis circumvents traditional perimeter defenses to gain initial access, facilitating lateral movement and the subsequent deployment of ransomware payloads. This campaign marks a strategic shift toward leveraging N-day vulnerabilities in critical network appliances to conduct large-scale extortion and enterprise-wide encryption.

  • Vulnerability Mechanics: Citrix Bleed 2

    • CVE-2025-5777 enables sensitive memory disclosure and session token leakage within Citrix NetScaler appliances.
    • Attackers leverage leaked session data to perform authentication bypass and session hijacking.
    • The vulnerability targets the core gateway/ADC layer, providing a direct gateway into the enterprise network.
  • Attack Vector: Deployment Lifecycle

    • Initial access is achieved through exploitation of the public-facing Citrix infrastructure.
    • Post-exploitation involves rapid lateral movement using stolen credentials and hijacked sessions.
    • The final stage utilizes Anubis-specific deployment toolsets for widespread ransomware execution.
  • Threat Actor Profile: Anubis Ransomware

    • Anubis focuses on high-impact, N-day vulnerabilities to facilitate rapid breach cycles.
    • The group targets diverse industry verticals through large-scale, automated exploitation campaigns.
    • Operations prioritize bypassing multi-factor authentication (MFA) by leveraging existing session tokens.
  • MITRE ATT&CK Mapping

    • T1190: Exploitation of public-facing Citrix NetScaler applications.
    • T1556: Modification of authentication processes via session hijacking.
    • T1486: Execution of data encryption for impact and extortion.
  • Detection & Mitigation Strategies

    • Prioritize immediate patching of all NetScaler, ADC, and Gateway appliances.
    • Monitor for IoCs associated with unusual session token re-use or memory disclosure anomalies.
    • Implement zero-trust principles to restrict lateral movement from edge devices into core network segments.

Related posts

  1. SecurityWeek — New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure
  2. eSecurity Planet — CVE-2026-8451: Citrix NetScaler Vulnerability Leaks Memory
  3. cyberscoop.com — Citrix patches a new NetScaler flaw with echoes of CitrixBleed
  4. feeds.feedburner.com — Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service
  5. penligent.ai — CVE-2026-8451, the NetScaler SAML IdP Memory Overread
  6. Support
  7. Beazley
  8. Techzine
  9. Horizon3
  10. Reddit
  11. Fortiguard
  12. Fortiguard
  13. Purpleshieldsecurity
  14. Csoonline
  15. Support
  16. Hkcert
  17. Mallory
  18. fieldeffect.com — New CitrixBleed-Like Flaw Exploited
  19. Labs
  20. Tenable
  21. Socradar
  22. Github
  23. Blog
  24. Tenable
  25. Secarma
  26. Nvd
  27. Radar
  28. Crowdsec
  29. Filestore

LINK COPIED TO CLIPBOARD