logo

CitrixBleed 2 (CVE-2025-5777) 7Steps to Dragonforce Ransomware | Huntress

ID: ca99cddd-9f34-5c5f-831d-1d9742fe8bdc

STIX ID: report--ca99cddd-9f34-5c5f-831d-1d9742fe8bdc

Feed Name: Huntress Blog

Threat Score
86/100

Date Published: 2026-07-09

Date Updated: 2026-07-19

...
...

**Executive summary:** Huntress observed a cluster of highly similar intrusions (Jan–Jun 2026) where an actor weaponized CVE-2025-5777 (CitrixBleed 2) to leak NetScaler heap memory, steal session tokens, hijack Citrix sessions, use a portable Windows LPE to gain SYSTEM, install remote-access tooling (ScreenConnect/Zoho/others), and deploy DragonForce ransomware; the report includes forensic details, tradecraft, and IoCs to guide detection and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.