HackMyIP
← Back to News
2026-07-02 The Hacker News

Anubis Ransomware Exploits Citrix Bleed 2 in Credential-Based Attacks

RansomwareVulnerabilitySupply Chain

Threat actors tied to the Anubis ransomware-as-a-service (RaaS) operation have been actively exploiting Citrix Bleed 2 (CVE-2025-5777), a critical authentication-bypass flaw in Citrix NetScaler ADC and Gateway appliances, to gain initial footholds inside enterprise networks. According to Arctic Wolf, affiliates combine this zero-day-style exploitation with valid VPN credentials obtained through prior compromises, credential stuffing, information-stealer logs, or initial access brokers (IABs). Anubis, which emerged in late 2024 as a rebrand of Sphinx ransomware and was formally advertised on the RAMP underground forum in February 2025, has already claimed 91 victims on its data leak site, with 11 added in June 2026 alone across healthcare, manufacturing, technology, financial services, and business sectors.

Once inside, operators lean heavily on legitimate Remote Management and Monitoring (RMM) tooling—including ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, and Total Software Deployment—to blend in with normal IT activity. After authenticating through compromised Cisco AnyConnect VPN accounts from hosting providers such as AS20473 (The Constant Company) and AS55286 (ServerMania), attackers pivot via RDP and SMB, harvest credentials, deploy RMM agents using PsExec, and exfiltrate data through cloud-transfer utilities. The group's reversible /WIPEMODE module adds additional pressure: it reduces all files to 0 KB with a single command, even after ransom payment, raising the stakes for victim organizations. Defenders should verify that no exposed RDP or SMB ports are reachable from the internet using a port scanner, and confirm whether stolen credentials appear in known leaks via an email breach checker.

More than 50% of Anubis victims are based in the United States, followed by the U.K., Australia, France, and Canada. The affiliate-friendly economics—an 80% profit split offered to partners—make the operation an attractive destination for Bring Your Own Vulnerable Driver (BYOVD) tradecraft and supply-chain credential reuse. Organizations running Citrix NetScaler ADC or Gateway appliances configured as a Gateway or AAA virtual server should patch CVE-2025-5777 (CVSS 9.3) immediately, enforce multi-factor authentication on all VPN and RMM access, audit RMM deployments for unauthorized agents, and harden SSL/TLS configurations on perimeter devices to limit the blast radius of credential-driven intrusions.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →