Tag: Supply Chain Credentials

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
News

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

Threat actors affiliated with the Anubis ransomware operation have been spotted using the Citrix Bleed 2 (CVE-2025-5777) vulnerability to acquire initial access. According to a research released this week by Arctic Wolf, common patterns in tradecraft have formed through the use of lawful Remote Management and Monitoring (RMM) equipment, credential access, and hands-on keyboard operations utilized for lateral movement, even though strategies vary within affiliates. Anubis affiliates routinely utilized genuine remote access and administration solutions, including ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, and Total Software Deployment, to blend in with typical IT operations while maintaining control of victim systems. Anubis is a ransomware-as-a-service (RaaS) gang ...