From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks
ID: 8ab75225-3ae2-5642-b1a8-8129aab5e960
STIX ID: report--8ab75225-3ae2-5642-b1a8-8129aab5e960
Feed Name: Arctic Wolf Blog
Arctic Wolf Labs documents multiple Anubis ransomware intrusions in 2026 driven by an affiliate RaaS model, highlighting initial access via valid VPN credentials and exploitation of CitrixBleed 2 (CVE-2025-5777), widespread abuse of legitimate RMM tools to blend with IT activity, hands-on-keyboard lateral movement using RDP and PsExec, credential collection (Mimikatz, browser password exports, ntds.dit copies), use of tunneling/proxying (cloudflared, SSH SOCKS, authenticated proxies) for egress, and pre-encryption exfiltration tooling; the report includes defensive guidance, high-priority mitigations, and references to IOCs and detection updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
