Threat actors linked to the Anubis ransomware operation have been actively exploiting the critical Citrix Bleed 2 vulnerability (CVE-2025-5777) to gain initial access to target networks, marking a significant escalation in the tactics employed by ransomware-as-a-service (RaaS) groups. This development coincides with revelations about other sophisticated RaaS outfits, including "The Gentlemen" utilizing a zero-day exploit and a custom Go-based backdoor, and a partnership between "VECT" and "TeamPCP" leveraging supply chain attacks for credential theft and subsequent ransomware deployment. The collective activities paint a stark picture of an increasingly professionalized and dangerous cybercrime landscape, where advanced techniques, strategic alliances, and persistent innovation drive a surge in global ransomware incidents.
Anubis Ransomware: Leveraging Citrix Bleed 2 for Initial Compromise
The Anubis ransomware group, a rebrand of the previously known Sphinx ransomware that first emerged in late 2024, has rapidly established itself as a formidable threat. Formally announced on the underground Ransomware and Advanced Malware Protection (RAMP) forum in February 2025, Anubis has since claimed 91 victims on its data leak site, with a notable 11 victims reported in June 2026 alone. The group’s modus operandi involves a sophisticated blend of initial access vectors and post-compromise activities designed to maximize impact and extort payments.
One of the primary initial access methods observed by security researchers, particularly Arctic Wolf, involves the exploitation of CVE-2025-5777, also known as Citrix Bleed 2. This critical vulnerability, with a CVSS score of 9.3, impacts Citrix NetScaler ADC and Gateway appliances. It allows attackers to bypass authentication when the appliance is configured as a Gateway or AAA virtual server, granting them unauthorized entry into victim networks. This vulnerability’s inclusion in CISA’s Known Exploited Vulnerabilities Catalog underscores its severity and the urgent need for organizations to patch affected systems.
Beyond direct vulnerability exploitation, Anubis affiliates also utilize valid VPN credentials for initial access, specifically noting logins through Cisco AnyConnect VPN from various hosting ASNs. The exact provenance of these credentials remains under investigation, but common procurement methods include prior data breaches, credential stuffing attacks, information stealer malware campaigns, or purchases from initial access brokers (IABs) on underground forums.
Once initial access is established, Anubis affiliates employ a consistent "hands-on-keyboard" approach, leveraging legitimate Remote Management and Monitoring (RMM) tools to maintain persistent control and blend in with normal IT activity. Tools such as ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, and Total Software Deployment are frequently observed in their campaigns. This tactic allows the attackers to evade detection by appearing as legitimate system administrators. Lateral movement within the compromised network is typically facilitated using Remote Desktop Protocol (RDP) and PsExec, enabling them to spread across systems and gain deeper access. In certain intrusions, attackers have also configured Cloudflare Tunnels (cloudflared) to establish covert communication channels to victim environments, further complicating detection and containment efforts.

A critical phase of Anubis attacks involves extensive credential harvesting to escalate privileges and facilitate deeper infiltration. Following this, various tools for data exfiltration are deployed, including S3 Browser, rclone, s5cmd, WinSCP, and PuTTY. This data theft often precedes the actual ransomware deployment, providing the threat actors with additional leverage for extortion through double-extortion tactics.
Anubis is also known for its aggressive data-wiping feature, /WIPEMODE, which significantly increases pressure on victims to pay the ransom. As detailed by Rubrik Zero Labs in July 2025, when activated, this module reduces files to 0 KB size, rendering them irrecoverable regardless of whether a ransom is paid. This "scorched-earth" capability underscores the irreversible damage Anubis can inflict, pushing victims into a difficult position where non-payment guarantees data loss. The RaaS model is further bolstered by attractive profit splits, with affiliates reportedly receiving 80% of the ransom amounts paid, incentivizing a wider pool of cybercriminals to join their operations.
The group’s targeting strategy is broad yet focused on high-value sectors. Healthcare, business services, manufacturing, technology, and financial services have been prominent victims. Geographically, over 50% of Anubis’s victims are located in the United States, followed by significant numbers in the United Kingdom, Australia, France, and Canada, reflecting a global reach with a strong emphasis on economically developed nations.
The Gentlemen: Zero-Day Exploits and Kernel-Level Evasion
Adding another layer of complexity to the ransomware threat landscape is "The Gentlemen" RaaS group, whose sophisticated tactics include the exploitation of zero-day vulnerabilities and the use of a custom Go-based backdoor. Kaspersky’s detailed analysis revealed The Gentlemen’s reliance on known vulnerabilities and compromised or weak login credentials for initial breaches, but their post-exploitation techniques highlight a high level of technical proficiency.
A particularly concerning aspect of The Gentlemen’s operations is their adoption of the Bring Your Own Vulnerable Driver (BYOVD) technique. Expel reported that the group weaponized a zero-day vulnerability in ktapi.sys, a driver associated with an API developed by Kontron. This allows them to obtain kernel-level access, effectively bypassing Windows security protections and disabling crucial endpoint detection and response (EDR) solutions from vendors like Microsoft, ESET, Palo Alto Networks, and SentinelOne. The ability to operate at the kernel level gives attackers unparalleled control and stealth, making detection and remediation exceedingly difficult. Marcus Hutchins, principal threat researcher at Expel, emphasized the persistent threat of BYOVD, noting that even the latest Windows versions with all exploit mitigations enabled do not provide complete protection against such sophisticated attacks. The mechanism by which The Gentlemen acquired knowledge of this specific zero-day vulnerability or the driver itself remains unclear, highlighting the elusive nature of advanced threat actor capabilities.
Beyond the BYOVD technique, The Gentlemen deploy a custom Go-based backdoor after reconnaissance and lateral movement, often achieved through Group Policy or PsExec. This backdoor, designed for remote command execution, is a potent tool for expanding their foothold within a compromised network. It collects system information and exfiltrates it to an external server (e.g., "81.177.215[.]15:9443") over a bidirectional TCP connection. The implant is capable of executing commands received from the operator using "cmd.exe" and can establish SOCKS proxy connections, enabling the group’s "red team" to pivot further within the target network and expand their scanning coverage. This comprehensive suite of capabilities allows The Gentlemen to adapt their attack chain dynamically based on the specific environment and their objectives.

VECT and TeamPCP: An Alliance for Industrialized Ransomware Deployment
The evolving RaaS ecosystem has also seen the emergence of strategic partnerships between cybercriminal entities, exemplified by the alliance between VECT and TeamPCP. Announced in March 2026, this partnership aims to combine TeamPCP’s expertise in supply chain attack-driven credential theft with VECT’s ransomware deployment capabilities.
Sophos Counter Threat Unit’s investigation into this alliance revealed that TeamPCP, which previously operated another ransomware brand called CipherForce (listing six victims in February 2026 before rebranding in May), now leverages VECT to deploy ransomware across organizations compromised through large-scale supply chain attacks, specifically mentioning the Trivy and LiteLLM campaigns. This model represents a significant shift towards "industrialized ransomware deployment," where initial access and ransomware execution are streamlined and scaled.
However, the VECT encryptor itself has been found to contain significant implementation flaws. Analyses by Check Point and JUMPSEC discovered that any file larger than 128 KB encrypted by VECT is permanently destroyed rather than securely encrypted, making recovery impossible even if a ransom is paid. This critical flaw potentially undermines the group’s extortion efforts. In response, TeamPCP issued a statement claiming they had never used VECT’s flawed encryptor in their attacks, asserting their preference for their own "private locker," CipherForce.
Despite these technical shortcomings, Sophos emphasizes the broader implications of such partnerships. The convergence of large-scale supply chain credential theft, a maturing RaaS operation, and mass underground forum mobilization creates an unprecedented model that significantly lowers the barrier to entry for cybercrime. This industrialized approach allows less technically proficient affiliates to participate in sophisticated campaigns, expanding the overall reach and impact of ransomware operations.
The Broader Implications and Future Outlook
The activities of Anubis, The Gentlemen, and the VECT/TeamPCP alliance highlight several critical trends in the contemporary cybersecurity landscape. The continuous exploitation of critical vulnerabilities like Citrix Bleed 2 underscores the persistent challenge organizations face in patching and securing their digital infrastructure. The agility of threat actors to quickly weaponize newly discovered flaws means that a proactive and continuous vulnerability management program is paramount.

The rise of BYOVD techniques and zero-day exploits, as demonstrated by The Gentlemen, signals a move towards more advanced defense evasion strategies. These techniques allow attackers to nullify even state-of-the-art EDR solutions, forcing security vendors and enterprises to invest in more robust, multi-layered security architectures that can detect anomalies at various stages of an attack, not just at the endpoint.
Furthermore, the increasing sophistication and collaboration within the RaaS ecosystem, characterized by attractive profit-sharing models and strategic alliances, are making cybercrime more accessible and scalable. This "industrialization" of ransomware lowers the technical bar for entry, potentially increasing the volume and velocity of attacks. The use of legitimate RMM tools and cloud-transfer utilities also indicates a deliberate effort by attackers to blend into normal network traffic, making detection more challenging for traditional security tools.
For organizations, the implications are severe. The risk of data loss, operational disruption, and significant financial penalties due to ransomware attacks is higher than ever. Robust data backup and recovery strategies, coupled with incident response plans that account for data-wiping functionalities like Anubis’s /WIPEMODE, are no longer optional but essential. Enhanced credential hygiene, multi-factor authentication, regular security audits, and employee training on phishing and social engineering tactics remain foundational defenses.
Ultimately, the ongoing evolution of ransomware operations necessitates a dynamic and adaptive defense posture. This includes not only technical safeguards but also a commitment to threat intelligence sharing among security vendors, government agencies, and private enterprises to stay ahead of rapidly evolving tactics and techniques employed by these increasingly dangerous cybercriminal groups. The battle against ransomware is a continuous arms race, demanding constant vigilance and innovation from the defenders.
