← BACK TO FEED
ransomwareCitrixBYOVDsupply chaincredential theft

Citrix Bleed 2, Rogue Drivers, and Poisoned Packages: Ransomware Groups Are Getting Creative

Ransomware groups including Anubis, The Gentlemen, and the VECT/TeamPCP alliance are employing increasingly sophisticated tactics, such as exploiting the critical Citrix Bleed 2 vulnerability (CVE-2025-5777), using legitimate remote management tools to blend in with normal IT activity, and leveraging a BYOVD zero-day to disable enterprise security solutions. The VECT/TeamPCP partnership represents a notable evolution in the threat landscape, combining supply chain credential theft with ransomware deployment at scale, though implementation flaws in VECT's encryptor have undermined its effectiveness. The FBI has issued a flash alert warning that credentials and data stolen in these campaigns pose a persistent long-term risk, as affiliated actors are likely to continue weaponizing them well after the initial breach.

Three separate ransomware operations are making headlines this week, and the common thread is a willingness to combine old-school credential abuse with some genuinely novel attack techniques. None of it is particularly reassuring.

Anubis Hits Citrix Hard

The Anubis ransomware crew, a rebranded version of Sphinx that only formally announced itself on the RAMP underground forum in February 2025, has been actively exploiting CVE-2025-5777, better known as Citrix Bleed 2. The flaw, rated a CVSS 9.3, lets attackers bypass authentication entirely on NetScaler ADC and Gateway appliances configured as Gateway or AAA virtual servers. That is a bad combination.

Arctic Wolf has been tracking the group's activity and published findings this week. Beyond Citrix exploitation, affiliates were also logging into Cisco AnyConnect VPNs using what appear to be pre-obtained credentials, sourced from who knows where. Initial access brokers, infostealers, credential stuffing. Take your pick.

Once in, the playbook is fairly standard: RDP and PsExec for lateral movement, a parade of legitimate remote management tools including ScreenConnect, Zoho Assist, MeshAgent, and UltraVNC to maintain persistence without looking suspicious, and Cloudflare Tunnels to phone home without raising alarms. Data gets staged and exfiltrated using S3 Browser, rclone, s5cmd, WinSCP, and PuTTY before the ransomware is deployed. Windows Defender gets switched off, Sophos gets uninstalled, logs get wiped.

The group has racked up 91 claimed victims already, 11 of them in June 2026 alone. Healthcare, manufacturing, financial services, and tech firms are the main targets, and over half the victims are in the US.

One thing that makes Anubis particularly unpleasant: it offers affiliates an 80% cut of ransom payments, which is generous by RaaS standards, and it includes a wiper module. When that WIPEMODE feature activates, files are zeroed out to 0 KB. They stay where they are, on disk, visible in directories, completely empty. The data is gone whether or not the victim pays. That is a pressure mechanism, and a fairly vicious one.

The Gentlemen and a Zero-Day Driver Nobody Knew Was Broken

Kaspersky has been looking at The Gentlemen, another RaaS outfit, and found a Go-based backdoor doing the rounds in their intrusions. The implant connects to an external command server over TCP, collects system info, executes commands via cmd.exe, and can establish a SOCKS proxy for pivoting through the target network. Functional, if not exactly sophisticated.

More interesting is what Expel uncovered alongside Kaspersky's findings. The Gentlemen have been using a zero-day vulnerability in ktapi.sys, a driver bundled with an API from hardware vendor Kontron. The attack is a BYOVD technique: bring your own vulnerable driver, load it into the kernel, and use it to kill security software. In this case, The Gentlemen used it to terminate endpoint protection from Microsoft, ESET, Palo Alto Networks, and SentinelOne.

Marcus Hutchins at Expel was blunt about it: even a fully patched Windows machine with all exploit mitigations turned on cannot guarantee protection against this approach. BYOVD is not new, but finding previously unknown vulnerable drivers to weaponise suggests these groups are putting real research time in.

How they found the vulnerability in ktapi.sys is still unknown.

Supply Chain Meets Ransomware: VECT and TeamPCP

Sophos has published research on the partnership between two groups called VECT and TeamPCP, a collaboration announced in March 2026 that combines supply chain credential theft with ransomware deployment at scale.

TeamPCP spent months injecting malicious code into open-source packages integrated into enterprise development pipelines, including tools like Trivy and LiteLLM, harvesting credentials from every organisation that built software using the compromised dependencies. VECT then deploys ransomware across the full list of compromised organisations. The FBI has now issued a flash alert warning about the campaign.

TeamPCP previously operated under the CipherForce brand, which listed six victims in February 2026 before rebranding in May. The VECT partnership is essentially an attempt to monetise their existing access at a much larger scale.

There is a catch. Check Point and JUMPSEC found a fairly significant bug in VECT's encryptor: any file larger than 128 KB gets permanently destroyed rather than encrypted. That undermines the basic premise of ransomware, which is that the victim can pay to get their data back. TeamPCP has publicly distanced themselves from VECT's encryptor, claiming they use their own private locker instead.

Sophos was measured but clear in its assessment. Technical flaws aside, the model itself is notable. A group that compromised software supply chains at scale, combined with a ransomware operation and mass coordination via underground forums, represents a more industrialised approach to extortion than most defenders are currently equipped to handle.

The FBI's parting warning is worth taking seriously: credentials stolen through supply chain compromise should be treated as a persistent threat long after the initial incident is closed.

READ NEXT
Ransomware Knocks Out Fairlife Milk Production Across the USNichirei Cyberattack Leaves Japan's Frozen Food Chain on IceFortiBleed Credential Harvest Is Directly Feeding INC and Lynx Ransomware Operations