< Back to all clusters
[CRIME] · United States, United Kingdom, Australia, France, Canada · 4 sources

Citrix Bleed vulnerability exploited, driving swift ransomware attacks

Within 24 hours of Citrix publishing advisory CTX696604 for CVE‑2026‑8451, threat actors began scanning and delivering an exploit against NetScaler appliances configured as SAML Identity Providers. Researchers tracking decoy infrastructure observed a coordinated campaign originating from a Frankfurt‑based hosting node, with the payload leveraging an out‑of‑bounds read in the appliance’s XML parser to leak session tokens.

Ransomware gangs, notably the Anubis group, have since weaponised the same Citrix Bleed flaws to gain initial footholds. Using compromised VPN or Citrix credentials, they deploy legit remote‑management tools, move laterally via RDP and PsExec, and encrypt data within a day. Victims span the United States, United Kingdom, Australia, France and Canada, with health, finance and technology sectors most targeted. The attackers also employ cloud‑relay proxies and data‑exfiltration utilities before encrypting files, often erasing logs and disabling security software.

The rapid exploitation highlights the danger of unauthenticated memory‑disclosure bugs and their immediate abuse by criminal cyber‑crime operations.