Executive Summary
In early July 2026, the Anubis ransomware group exploited a critical vulnerability known as Citrix Bleed 2 (CVE-2025-5777) in Citrix NetScaler appliances to gain unauthorized access to enterprise networks. This flaw allowed attackers to bypass multi-factor authentication by stealing session tokens, leading to the compromise of 91 organizations across sectors such as healthcare, financial services, manufacturing, and technology. The attackers utilized legitimate remote management tools to maintain persistence and evade detection, culminating in the deployment of ransomware that encrypted critical data and disrupted operations.
This incident underscores the persistent threat posed by unpatched vulnerabilities and the sophisticated tactics employed by ransomware groups. The exploitation of Citrix Bleed 2 highlights the importance of timely patch management and the need for comprehensive monitoring of remote access tools to detect and prevent unauthorized activities.
Why This Matters Now
The exploitation of Citrix Bleed 2 by ransomware groups like Anubis demonstrates the critical need for organizations to promptly apply security patches and monitor for unauthorized use of remote management tools. Delayed patching and inadequate oversight can lead to significant operational disruptions and data breaches.
Attack Path Analysis
Attackers exploited the CitrixBleed 2 vulnerability (CVE-2025-5777) in Citrix NetScaler appliances to steal session tokens, bypassing multi-factor authentication and gaining initial access. They then escalated privileges by creating rogue accounts and deploying remote management tools. Utilizing these tools, they moved laterally within the network to identify and access critical systems. Established command and control channels allowed them to maintain persistent access and coordinate their activities. Sensitive data was exfiltrated using encrypted channels to evade detection. Finally, the deployment of DragonForce ransomware encrypted data, leading to operational disruption and financial demands.
Kill Chain Progression
Initial Compromise
Description
Exploited CitrixBleed 2 vulnerability (CVE-2025-5777) to steal session tokens, bypassing multi-factor authentication and gaining unauthorized access.
Related CVEs
CVE-2025-5777
CVSS 7.5A critical pre-authentication vulnerability in Citrix NetScaler appliances allows unauthenticated remote attackers to steal session tokens, bypassing multi-factor authentication.
Affected Products:
Citrix NetScaler ADC – 13.1-21.50 and earlier
Citrix NetScaler Gateway – 13.1-21.50 and earlier
Exploit Status:
exploited in the wildCVE-2026-2699
CVSS 9.8A critical vulnerability in Progress ShareFile Storage Zone Controller v5.x allows unauthenticated remote attackers to access configuration pages and potentially achieve remote code execution.
Affected Products:
Progress Software ShareFile Storage Zone Controller – 5.x
Exploit Status:
no public exploitCVE-2026-2699
CVSS 9.8A critical vulnerability in Progress ShareFile Storage Zone Controller v5.x allows unauthenticated remote attackers to access configuration pages and potentially achieve remote code execution.
Affected Products:
Progress Software ShareFile Storage Zone Controller – 5.x
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Supply Chain Compromise
Compromise Software Supply Chain
Compromise Software Dependencies and Development Tools
Compromise Hardware Supply Chain
Valid Accounts
Command and Scripting Interpreter
Impair Defenses
Obfuscated Files or Information
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities by installing applicable security patches
Control ID: 6.2
NYDFS 23 NYCRR 500 – Application Security
Control ID: 500.08
DORA – ICT Risk Management Framework
Control ID: Article 6
CISA ZTMM 2.0 – Data Security
Control ID: Pillar 3: Data
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Supply chain threats targeting AI coding tools and trusted software create severe risks for development environments and automated systems.
Information Technology/IT
ShareFile and Citrix vulnerabilities expose critical infrastructure to ransomware attacks, compromising encrypted traffic and zero trust implementations.
Financial Services
PCI compliance violations through unencrypted traffic and lateral movement attacks threaten payment systems and sensitive financial data protection.
Health Care / Life Sciences
HIPAA compliance breaches via compromised encryption and segmentation failures expose patient data to exfiltration and ransomware attacks.
Sources
- ⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and Morehttps://thehackernews.com/2026/07/weekly-recap-sharefile-threat-citrix.htmlVerified
- Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentialshttps://thehackernews.com/2026/07/ransomware-groups-turn-to-citrix-bleed.htmlVerified
- Anubis Ransomware Rides Citrix Bleed 2 Past MFA: 91 Victims and a Playbook Built on Legitimate Toolshttps://breached.company/anubis-ransomware-citrix-bleed-2-91-victims-2026/Verified
- Critical CVE-2026-2699 and CVE-2026-2701 Vulnerabilities Force Immediate Shutdown of Progress ShareFile Storage Zone Controller v5.xhttps://www.rescana.com/post/critical-cve-2026-2699-and-cve-2026-2701-vulnerabilities-force-immediate-shutdown-of-progress-sharefile-storage-zone-conVerified
- Progress Pulls ShareFile Storage Zone Controllers Offline, No Patch Availablehttps://www.techtimes.com/articles/320148/20260711/progress-pulls-sharefile-storage-zone-controllers-offline-no-patch-available.htmVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial access would likely have been constrained, limiting their ability to exploit the vulnerability across multiple workloads.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely have been limited, reducing their access to critical systems.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement would likely have been restricted, limiting their ability to access critical systems.
Control: Multicloud Visibility & Control
Mitigation: The attacker's command and control channels would likely have been detected and disrupted, reducing their ability to coordinate activities.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts would likely have been hindered, limiting the amount of data exfiltrated.
The attacker's ability to deploy ransomware would likely have been constrained, reducing the scope of operational disruption.
Impact at a Glance
Affected Business Functions
- File Sharing Services
- Remote Access Management
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive corporate documents and user credentials.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Encrypted Traffic (HPE) to secure data in transit and prevent unauthorized access.
- • Deploy East-West Traffic Security to monitor and control lateral movement within the network.
- • Utilize Zero Trust Segmentation to enforce least privilege access and limit attacker movement.
- • Establish Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
- • Enforce Egress Security & Policy Enforcement to prevent unauthorized data exfiltration and command and control communications.



