Ransomware Gangs Exploit Citrix Bleed 2, BYOVD Tactics, Stolen Credentials

Anubis ransomware affiliates are exploiting the Citrix Bleed 2 vulnerability (CVE-2025-5777) to break into networks. CVSS 9.3. That’s about as bad as it gets.

Arctic Wolf tracked the activity. Their report shows a consistent pattern: exploit the Citrix flaw, abuse legitimate RMM tools, grab credentials, move laterally. Rinse and repeat.

Anubis uses ScreenConnect, Zoho Assist, MeshAgent, UltraVNC — normal IT tools that blend in perfectly. They don’t need custom malware for persistence when these tools already look legitimate to defenders.

The ransomware crew claims 91 victims so far. Healthcare, manufacturing, tech, financial services. Over half are in the US.

Anubis has a nasty trick: an irreversible data-wipe mode that zeroes files to 0 KB. Even if you pay, those files are gone. That ups the pressure to pay fast, before the wiper activates.

Separately, The Gentlemen ransomware group is using a Go-based backdoor and a zero-day driver exploit (BYOVD) to kill security processes from Microsoft, ESET, Palo Alto Networks, and SentinelOne. They weaponized a driver called ktapi.sys from Kontron — a signed, legitimate driver with a vulnerability that lets attackers gain kernel-level access.

Both groups show the same trend: ransomware operators are getting better at living off the land. They don’t need flashy 0-days when Citrix CVEs and signed drivers do the job.

References