logo

From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks

ID: 8ab75225-3ae2-5642-b1a8-8129aab5e960

STIX ID: report--8ab75225-3ae2-5642-b1a8-8129aab5e960

Feed Name: Arctic Wolf Blog

Threat Score
80/100

Date Published: 2026-07-01

Date Updated: 2026-07-01

...
...

Arctic Wolf Labs documents multiple Anubis ransomware intrusions in 2026 driven by an affiliate RaaS model, highlighting initial access via valid VPN credentials and exploitation of CitrixBleed 2 (CVE-2025-5777), widespread abuse of legitimate RMM tools to blend with IT activity, hands-on-keyboard lateral movement using RDP and PsExec, credential collection (Mimikatz, browser password exports, ntds.dit copies), use of tunneling/proxying (cloudflared, SSH SOCKS, authenticated proxies) for egress, and pre-encryption exfiltration tooling; the report includes defensive guidance, high-priority mitigations, and references to IOCs and detection updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.