
Security researchers have tracked at least three ransomware operations — Anubis, The Gentlemen, and a partnership between VECT and TeamPCP — all exploiting the same combination of techniques: they use a critical flaw in Citrix NetScaler (nicknamed “Citrix Bleed 2”) to break into corporate networks, then immediately use a Windows driver exploit to kill endpoint security software before deploying ransomware.
The Citrix flaw, CVE-2025-5777 (CVSS 9.3), allows attackers to steal valid session tokens from internet-facing NetScaler devices without any login credentials — effectively giving them a copy of someone’s access badge. Once inside, they use a technique called BYOVD (Bring Your Own Vulnerable Driver), where they install a legitimate but unpatched hardware driver that grants access to the Windows kernel itself, letting them shut down antivirus and endpoint detection tools from the inside. The combination means attackers can enter a network silently, go invisible to defenders, and encrypt files before anyone notices.
How to check if you’re affected
Affected versions of NetScaler ADC and NetScaler Gateway include 14.1 before 14.1-43.56 and version 13.1 before 13.1-58.32. If your organization uses Citrix NetScaler for remote access or application delivery, your IT team should check the installed version in the NetScaler administration console and apply the available security patch immediately. Patches have been available since 2025 but exploitation by ransomware groups is still ongoing.
