Hackers Exploit CitrixBleed 2 to Hijack MFA-Protected Sessions and Deploy DragonForce Ransomware
ID: d9f50179-fcb1-5a8a-97ae-ad1985b0f4f3
STIX ID: report--d9f50179-fcb1-5a8a-97ae-ad1985b0f4f3
Feed Name: GBHackers
Active exploitation of CitrixBleed 2 (CVE-2025-5777) against NetScaler ADC/Gateway appliances is being used to leak session tokens and bypass MFA; attackers then escalate privileges to NT AUTHORITY\ SYSTEM, create rogue administrator accounts, install remote-access tooling (ScreenConnect/Zoho Assist), and deploy DragonForce ransomware. The report provides observed TTPs, IoCs (filenames, SHA256 hashes, account/hostnames, relay domains), and recommends immediate patching, terminating outstanding sessions, and preserving gateway logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
