RMM-ber this ransomware.
ID: 93676d40-d47d-59ee-be21-7c9dc84a1e4e
STIX ID: report--93676d40-d47d-59ee-be21-7c9dc84a1e4e
Feed Name: The CyberWire
Threat Score
Arctic Wolf Labs details a series of 2026 Anubis ransomware intrusions where affiliates gained initial access via stolen VPN credentials and exploitation of CitrixBleed 2, then blended into legitimate IT activity by deploying RMM tools, using RDP and PsExec for lateral movement, stealing credentials, and establishing tunnels/proxies for persistence and exfiltration, with the research outlining detectable TTPs defenders can interrupt before encryption.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
