logo

RMM-ber this ransomware.

ID: 93676d40-d47d-59ee-be21-7c9dc84a1e4e

STIX ID: report--93676d40-d47d-59ee-be21-7c9dc84a1e4e

Feed Name: The CyberWire

Threat Score
78/100

Date Published: 2026-09-05

Date Updated: 2026-09-10

...
...

Arctic Wolf Labs details a series of 2026 Anubis ransomware intrusions where affiliates gained initial access via stolen VPN credentials and exploitation of CitrixBleed 2, then blended into legitimate IT activity by deploying RMM tools, using RDP and PsExec for lateral movement, stealing credentials, and establishing tunnels/proxies for persistence and exfiltration, with the research outlining detectable TTPs defenders can interrupt before encryption.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.