What We Know
Multiple security reports describe an active Anubis ransomware campaign that investigators link to exploitation of the Citrix “Bleed 2” pre‑authentication flaw (CVE-2025-5777) in Citrix NetScaler/ADC. Reporting says the operation has claimed 91 victims overall, including 11 victims in June 2026, and that attackers have used the Citrix flaw to gain initial access and move to encryption while defeating multi‑factor authentication protections before carrying out encryption.
Analysts from Arctic Wolf and other observers detail a pattern of combined techniques: exploiting CitrixBleed 2, abusing stolen VPN credentials and supply‑chain or service credentials, and leveraging legitimate remote‑management tooling (including RMM products and tunneling tools such as cloudflared, per Arctic Wolf) to maintain access and stage ransomware. Coverage across The Hacker News, InfoSec Today, Techzine, and others highlights that Anubis affiliates are using a mix of credential abuse, BYOVD (bring your own VPN/device) and legitimate‑access techniques rather than relying solely on classic exploit‑and‑encrypt methods.
Source Comparison
Aligned reportingCorroborates
- techtimes.com↗Reports the same campaign title and victim tally, stating the operation has claimed 91 victims (11 in June 2026) and links the activity to exploitation of Citrix Bleed 2 that bypasses MFA before encryption.
- insight.tmcnet.com↗Summarizes Arctic Wolf’s finding that Anubis affiliates have been exploiting Citrix Bleed 2 for ransomware intrusions, supporting the briefing’s attribution to Arctic Wolf.
- arcticwolf.com↗Arctic Wolf’s blog documents the tools and techniques observed — CitrixBleed 2 exploitation, stolen VPN and service credentials, RMM/remote‑management tooling and cloudflared — matching the briefing’s technical pattern and MFA bypass claims.
- techzine.eu↗Describes investigations showing attackers combined stolen VPN credentials with CitrixBleed 2 (CVE‑2025‑5777) and remote management tools to carry out Anubis intrusions, aligning with the briefing’s account.
- thehackernews.com↗Highlights ransomware groups’ use of Citrix Bleed 2 alongside BYOVD and supply‑chain credentials, corroborating the briefing’s point that affiliates use credential abuse and legitimate‑access techniques.
- infosectoday.io↗Reports that actors tied to Anubis have been observed exploiting Citrix Bleed 2 and leveraging BYOVD and supply‑chain credentials, supporting the briefing’s description of the attack methods.
- cysecurity.news↗Notes renewed Anubis activity and indicates attackers were found abusing Citrix remote‑access vulnerabilities, corroborating the briefing’s link between Anubis activity and CitrixBleed 2 exploitation.