CitrixBleed 2 (CVE-2025-5777) 7Steps to Dragonforce Ransomware | Huntress
ID: ca99cddd-9f34-5c5f-831d-1d9742fe8bdc
STIX ID: report--ca99cddd-9f34-5c5f-831d-1d9742fe8bdc
Feed Name: Huntress Blog
Threat Score
**Executive summary:** Huntress observed a cluster of highly similar intrusions (Jan–Jun 2026) where an actor weaponized CVE-2025-5777 (CitrixBleed 2) to leak NetScaler heap memory, steal session tokens, hijack Citrix sessions, use a portable Windows LPE to gain SYSTEM, install remote-access tooling (ScreenConnect/Zoho/others), and deploy DragonForce ransomware; the report includes forensic details, tradecraft, and IoCs to guide detection and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
