logo

Hackers Exploit CitrixBleed 2 to Hijack MFA-Protected Sessions and Deploy DragonForce Ransomware

ID: d9f50179-fcb1-5a8a-97ae-ad1985b0f4f3

STIX ID: report--d9f50179-fcb1-5a8a-97ae-ad1985b0f4f3

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-07-10

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

Active exploitation of CitrixBleed 2 (CVE-2025-5777) against NetScaler ADC/Gateway appliances is being used to leak session tokens and bypass MFA; attackers then escalate privileges to NT AUTHORITY\ SYSTEM, create rogue administrator accounts, install remote-access tooling (ScreenConnect/Zoho Assist), and deploy DragonForce ransomware. The report provides observed TTPs, IoCs (filenames, SHA256 hashes, account/hostnames, relay domains), and recommends immediate patching, terminating outstanding sessions, and preserving gateway logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.