New Ransomware Tactics: Citrix Bleed and Supply Chain Risk
We analyze how the Anubis group uses the Citrix Bleed 2 vulnerability and BYOVD techniques to infiltrate corporate networks with high efficiency.

The Resurgence of Persistent Threats: The Citrix Bleed 2 Case
The cybersecurity landscape is facing a new challenge. Recent investigations have revealed that ransomware groups associated with the Anubis operation have refined their modus operandi, focusing their efforts on exploiting the vulnerability known as Citrix Bleed 2 (CVE-2025-5777). This flaw allows attackers to gain initial access to critical infrastructure, bypassing perimeter defenses that, until recently, were considered robust.
The Evolution of Hacking: BYOVD and Lateral Movement
Beyond initial access, attackers are employing a sophisticated combination of legitimate Remote Management and Monitoring (RMM) tools and Bring Your Own Vulnerable Driver (BYOVD) techniques. This strategy not only allows them to evade detection by Endpoint Detection and Response (EDR) solutions but also facilitates lateral movement within the network, a critical phase in any large-scale hack.
"Although tactics differ between affiliates, common patterns in the use of legitimate tools and hands-on-keyboard procedures demonstrate a worrying professionalization of cybercrime."
It is essential to remember that the attack surface is dynamic. As we saw in the case of ChocoPoC: The dangerous hack lurking for vulnerability researchers, attackers always look for the weakest link, whether in management software or supply chain credentials.
Mitigation Recommendations
To protect against these threats, organizations must adopt a defense-in-depth approach:
- Critical Updates: Prioritize patching all internet-facing Citrix devices.
- RMM Monitoring: Audit and restrict the use of unauthorized remote management tools.
- Credential Hygiene: Implement phishing-resistant multi-factor authentication (MFA) to prevent supply chain credentials from becoming an entry point.
Modern cybersecurity allows for no complacency. The ability of ransomware groups to adapt to new vulnerabilities requires IT teams to maintain a posture of constant vigilance and the ability to respond rapidly to any anomalous behavior in their systems.
Source: The Hacker News (https://thehackernews.com/2026/07/ransomware-groups-turn-to-citrix-bleed.html)
Related articles
7 de septiembre de 2026
Cybersecurity: New ScreenConnect vulnerability facilitates attacks
Researchers have detected a four-stage infection chain that uses ScreenConnect to compromise systems through malicious scripts.
30 de agosto de 2026
Breach at Manchester Airports Group: The hack exposing 86 GB of data
The group FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group, revealing sensitive passenger and booking information.
23 de agosto de 2026
Hackers infect Android car systems: the new vulnerability
A supply chain attack is turning Android-based automotive multimedia systems into part of a botnet, putting driver security at risk.
16 de agosto de 2026
AmnesiaStealer: The new hack compromising macOS security
We analyze AmnesiaStealer, a macOS malware that enables remote browser control and puts user privacy at risk.
Loading comments...