Dettaglio notizia
| Data | 01/07/2026 |
| Titolo | Anubis Ransomware Expanded Through Forum Branding and CitrixBleed 2 Intrusions |
| Contesto | The Anubis ransomware operation has grown into a structured cybercriminal ecosystem that combines public branding, affiliate recruitment, and multi-platform extortion services. Researchers linked the group’s leak sites, onion infrastructure, forum accounts, and the recurring "Anubis Media" persona into a unified operation that promoted ransomware and data-extortion offerings across underground communities including XSS, BreachForums, ReHub, and RAMP, as well as X. The group reportedly listed 83 victims between February 2025 and June 2026, sought corporate access in the United States, Canada, Europe, and Australia, and advertised support for Windows, Linux, NAS, and ESXi environments with capabilities such as privilege escalation, shadow copy removal, network-wide deployment, and multiple encryption modes. Separate incident reporting tied Anubis-linked intrusions to practical affiliate tradecraft centered on stolen VPN credentials and exploitation of CitrixBleed 2 ( CVE-2025-5777) on Citrix NetScaler appliances. In observed attacks, operators blended into normal administration by deploying legitimate remote-management tools including ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, Total Software Deployment, and mRemoteNG, then moved laterally with RDP, SMB, and PsExec. They also harvested credentials with Mimikatz, browser password exports, and ntds.dit theft, used tools such as S3 Browser, rclone, s5cmd, WinSCP, and PuTTY for exfiltration staging, and in some cases established fallback access through cloudflared, authenticated proxies, and SSH SOCKS tunnels, including activity involving Synology NAS devices. |
| Fonte | https://mallory.ai/stories/019f1d2a-4f07-7c99-9993-d7767fa6cb01 |
| Discussione? | Parliamone sul Forum |