Tag: Ransomware Groups

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
News

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

Threat actors affiliated with the Anubis ransomware operation have been spotted using the Citrix Bleed 2 (CVE-2025-5777) vulnerability to acquire initial access. According to a research released this week by Arctic Wolf, common patterns in tradecraft have formed through the use of lawful Remote Management and Monitoring (RMM) equipment, credential access, and hands-on keyboard operations utilized for lateral movement, even though strategies vary within affiliates. Anubis affiliates routinely utilized genuine remote access and administration solutions, including ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, and Total Software Deployment, to blend in with typical IT operations while maintaining control of victim systems. Anubis is a ransomware-as-a-service (RaaS) gang ...
Ukraine Police Arrest Suspect Linked to LockBit and Conti Ransomware Groups
News

Ukraine Police Arrest Suspect Linked to LockBit and Conti Ransomware Groups

A local individual who is believed to have provided his services to the LockBit and Conti ransomware organizations has been arrested, according to the announcement made by the Ukrainian Cyber Police. The 28-year-old Kharkiv native, who will remain nameless, is purportedly an expert in the creation of crypters, which are used to obfuscate and encrypt malicious payloads to prevent detection by security tools. The Conti and LockBit ransomware syndicates are thought to have received the software, which they used to cover up the file-encrypting virus and carry out successful assaults. Additionally, a translated version of the agency's statement claims that in the end of 2021, members of the [Conti] group implanted hidden malware into the computer networks of businesses in the Netherla...