Anubis Ransomware Leverages Citrix Exploit and IT Admin Tools
A ransomware operation linked to Anubis is breaking into networks using a CitrixBleed 2 flaw and stolen VPN credentials, then moving quietly through systems with trusted remote admin tools before deploying encryption. Attackers rely on ScreenConnect, Zoho Assist, MeshAgent, and tunnelling utilities like cloudflared to maintain access while extracting Active Directory data and sensitive credentials. The campaign spans multiple environments and ends with full system encryption after extensive lateral movement and data exfiltration.
Source: Arctic Wolf Labs
Read more: CyberSecBrief














