Ransomware Groups

Overview

The ransomware landscape is evolving rapidly, with threat actors adopting new exploitation chains that combine Citrix Bleed 2, Bring Your Own Vulnerable Driver (BYOVD), and supply‑chain credential theft. Recent investigations by Arctic Wolf, Kaspersky, and Sophos reveal how groups like Anubis, The Gentlemen, and TeamPCP/VECT are weaponizing these techniques to bypass defenses and accelerate ransomware deployment.

Anubis Ransomware and Citrix Bleed 2 Exploitation

The Anubis RaaS operation, a rebrand of Sphinx ransomware, has been observed exploiting Citrix Bleed 2 (CVE‑2025‑5777) — a critical flaw in Citrix NetScaler ADC and Gateway that allows authentication bypass when configured as a Gateway or AAA virtual server.

Key tactics identified by Arctic Wolf:

  • Exploitation of Citrix Bleed 2 for initial access.
  • Use of legitimate RMM tools like ScreenConnect, Zoho Assist, and UltraVNC to blend with normal IT activity.
  • Credential harvesting and lateral movement via RDP, PsExec, and Cloudflare Tunnels.
  • Data exfiltration using cloud transfer tools such as rclone, WinSCP, and S3 Browser.

Anubis affiliates also disable endpoint defenses and erase logs to obscure forensic traces. Their /WIPEMODE module reduces files to 0 KB even after payment, creating a “scorched‑earth” pressure tactic that forces victims to pay quickly.

The Gentlemen RaaS and BYOVD 0‑Day Exploitation

Kaspersky has uncovered a Go‑based backdoor used by The Gentlemen RaaS group, which leverages BYOVD (Bring Your Own Vulnerable Driver) techniques to gain kernel‑level access.

Attack chain highlights:

  • Go‑based backdoor establishes two‑way TCP communication with C2 server 81.177.215[.]15:9443.
  • Command execution and SOCKS proxy setup for network pivoting.
  • BYOVD exploit using ktapi.sys to bypass Windows security and terminate protected processes from Microsoft, ESET, and SentinelOne.

Security researchers warn that BYOVD remains a major enterprise risk, allowing attackers to disable endpoint protection even on fully patched systems.

VECT and TeamPCP Supply‑Chain Credential Partnership

Sophos Counter Threat Unit has exposed a formal partnership between VECT and TeamPCP, combining supply‑chain credential theft with ransomware deployment.

Key findings:

  • Credential theft via Trivy and LiteLLM attacks feeds VECT’s ransomware campaigns.
  • CipherForce rebrand marks TeamPCP’s transition to a larger RaaS ecosystem.
  • Encryption flaws in VECT cause files larger than 128 KB to be destroyed instead of encrypted.

Despite technical issues, the VECT/TeamPCP alliance represents a new model of industrialized ransomware, where credential brokers, RaaS operators, and supply‑chain attackers collaborate to lower the barrier to entry for cybercrime.

Defensive Recommendations

To mitigate these emerging ransomware vectors:

  • Patch Citrix NetScaler and Gateway immediately to close CVE‑2025‑5777.
  • Audit VPN and RMM usage for unauthorized connections.
  • Monitor for BYOVD driver activity and block unsigned drivers.
  • Strengthen supply‑chain security through vendor risk assessments and credential rotation.
  • Implement behavior‑based detection to catch RMM and PsExec abuse early.

Expert in the Cloud Insight

The rise of Citrix Bleed 2, BYOVD, and supply‑chain credential attacks marks a new phase in ransomware industrialization. Groups like Anubis and The Gentlemen are blurring the lines between legitimate IT tools and malicious operations, making traditional defenses less effective.

For security leaders, the path forward is clear: treat remote management and driver integrity as critical attack surfaces, and invest in continuous threat intelligence to stay ahead of RaaS innovation.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.