Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
Threat actors linked to the Anubis ransomware operation have been seen abusing Citrix Bleed 2 to gain initial access, specifically via CVE-2025-5777 affecting Citrix NetScaler ADC and Gateway (CVSS 9.3). The same reporting highlights their use of remote access tools, credential theft, RDP/PsExec for lateral movement, and follow-on data theft before deploying ransomware.
In related ransomware activity, Kaspersky described The Gentlemen RaaS using a Go-based backdoor and weaponizing a BYOVD scenario involving the ktapi.sys driver for kernel-level abuse, while Sophos reported a VECT and TeamPCP supply-chain partnership that enables ransomware deployment across victims of Trivy and LiteLLM supply chain attacks. These developments matter because they combine high-impact exploitation and credential compromise with scalable “industrialized” deployment tactics that lower the barrier for attackers.