Ransomware groups turn to a dangerous new combination of exploits, driver abuse, and stolen supply chain credentials, and SMBs running unpatched Citrix environments are directly in the crosshairs.

The tactics behind these attacks have grown precise enough that standard perimeter defenses no longer provide adequate protection on their own.

Key takeaways

  • Citrix Bleed 2 (CVE-2025-5777) is actively exploited by the Anubis ransomware operation to gain initial access, making unpatched Citrix NetScaler instances an urgent remediation priority.
  • Ransomware groups turn legitimate Remote Management and Monitoring (RMM) tools into cover, blending malicious activity into normal IT traffic where standard log review will not catch it.
  • Bring Your Own Vulnerable Driver (BYOVD) techniques let attackers disable endpoint security from inside the Windows kernel, neutralizing tools your team may rely on as a primary defense.
  • Supply chain credential abuse means attackers may already hold valid usernames and passwords sourced from a vendor or partner breach, so your own password hygiene alone is not sufficient.

Ransomware groups turn their focus wherever defenses are weakest, and the current threat landscape shows a clear pivot toward three compounding attack vectors: a newly disclosed Citrix vulnerability, a kernel-level driver abuse technique, and credentials harvested through supply chain compromise. Each vector is dangerous on its own. Combined, they represent a coordinated escalation that smaller organizations are poorly positioned to absorb.

The Anubis ransomware operation has been observed exploiting CVE-2025-5777, referred to publicly as Citrix Bleed 2. This vulnerability targets Citrix NetScaler environments and gives threat actors a pathway to initial access without requiring a stolen password. If your organization runs Citrix for remote access or application delivery and has not applied the relevant patch, that single gap can be the only opening an attacker needs.

Citrix NetScaler is widely deployed across mid-market and enterprise firms, but many SMBs also rely on it for secure remote connectivity. The name Citrix Bleed 2 is not accidental. It echoes the original Citrix Bleed vulnerability from 2023, which ransomware groups exploited extensively before most organizations had finished patching. The pattern is repeating, and the window to act is narrow.

Bring Your Own Vulnerable Driver, or BYOVD, is the second technique drawing attention in this threat cluster. The attack works by loading a legitimate but outdated and vulnerable driver into the Windows kernel. Once that driver is resident, attackers use it to terminate or neuter endpoint detection and response (EDR) tools. Your security software appears to be running normally from the outside, while the attacker has quietly blinded it from within.

BYOVD is not a new concept, but its inclusion in ransomware affiliate playbooks signals growing sophistication at the operational level. Ransomware-as-a-service groups provide affiliates with toolkits, and when BYOVD utilities become a standard component of those toolkits, even moderately skilled attackers gain the ability to disable enterprise-grade endpoint protection. SMBs that invested in EDR as a primary defense layer should treat BYOVD as a direct challenge to that investment.

Supply chain credential abuse rounds out this cluster. Rather than attacking your environment head-on, threat actors obtain valid credentials by breaching a software vendor, managed service provider, or other third party with privileged access to your systems. Those credentials arrive already authenticated. Multifactor authentication gaps, legacy VPN access, and RMM platform accounts are common entry points.

This supply chain angle connects directly to the RMM tooling patterns researchers observed while tracking the Anubis operation. Common behaviors emerged across affiliates, including use of legitimate Remote Management and Monitoring tools, credential access techniques, and hands-on-keyboard lateral movement. RMM tools are attractive to attackers precisely because they generate traffic that looks identical to normal administrative work.

For IT managers, this creates a detection problem that goes well beyond signatures and alerts. An attacker inside your environment using a tool your own team uses every day will not trigger most standard log reviews until encryption has already begun. Behavioral analytics, privileged access controls, and strict RMM session auditing become critical compensating controls in this scenario.

The hands-on-keyboard element of these attacks also matters for incident response planning. Automated ransomware that deploys without human involvement can sometimes be caught by heuristic controls. Human-operated ransomware is different. A real person is navigating your environment, adapting in real time, noticing your defenses, working around them, and escalating privileges before triggering the payload.

SMBs often assume they fall below the threshold of interest for sophisticated threat actors. The ransomware-as-a-service model has eliminated that assumption. Affiliates operate independently, targeting any organization that offers a viable ransom opportunity. An SMB running an unpatched Citrix instance is as attractive as a larger firm, particularly when that smaller company is connected to a higher-value supply chain.

Patching CVE-2025-5777 on any Citrix NetScaler deployment should be treated as an emergency remediation task, not a scheduled maintenance item. Your IT team or managed security provider should confirm patch status before the end of the current business week. Where patching cannot happen immediately, compensating controls such as network segmentation and access restrictions should be applied to limit exposure.

Reviewing which vendors and partners hold RMM or privileged access to your environment is an equally important near-term action. For each account, confirm that access is gated by multifactor authentication, that sessions are logged, and that access scopes are limited to what is operationally necessary. Unused or dormant vendor accounts should be disabled until actively needed.

BYOVD defense requires a direct conversation with your endpoint security vendor. Confirm that your EDR solution includes driver blocklist enforcement or equivalent kernel-level tamper protection. Not all EDR products handle this equally, and asking your vendor a pointed question about BYOVD resilience is a legitimate procurement and renewal discussion, not a technical edge case.

These three converging techniques reflect a maturation in ransomware affiliate tradecraft that demands a parallel shift in how SMBs think about security posture. Reactive patching cycles, single-layer endpoint tools, and implicit trust in vendor access are no longer defensible positions. Closing these gaps now costs a fraction of what a ransomware recovery will demand later.

TeckPath Perspective: When ransomware groups turn to techniques that abuse trusted tools, valid credentials, and kernel-level blind spots at the same time, the SMBs most at risk are those still treating security as a checkbox rather than an operational discipline, and that is exactly the gap TeckPath is built to close.

The attackers have already updated their playbook. The only question is whether your defenses have kept pace.

Need help with Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials: What SMBs Must Know Now?

TeckPath helps Calgary, Toronto, and Canadian businesses manage, secure, and modernize IT — with 24/7 support and SOC 2 Type II practices.