CVE Tools
Back to feed
Exploited in the wild netscaler anubis ransomware cloudflared citrix

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

The Hacker News·By The Hacker News··5 min read
CVE Tools coverage

Threat actors linked to the Anubis ransomware operation have been seen abusing Citrix Bleed 2 to gain initial access, specifically via CVE-2025-5777 affecting Citrix NetScaler ADC and Gateway (CVSS 9.3). The same reporting highlights their use of remote access tools, credential theft, RDP/PsExec for lateral movement, and follow-on data theft before deploying ransomware.
In related ransomware activity, Kaspersky described The Gentlemen RaaS using a Go-based backdoor and weaponizing a BYOVD scenario involving the ktapi.sys driver for kernel-level abuse, while Sophos reported a VECT and TeamPCP supply-chain partnership that enables ransomware deployment across victims of Trivy and LiteLLM supply chain attacks. These developments matter because they combine high-impact exploitation and credential compromise with scalable “industrialized” deployment tactics that lower the barrier for attackers.