Cyber Security Published on July 9, 2026
Initial access broker weaponizes CitrixBleed 2 to deploy DragonForce ransomware
Huntress investigated roughly half a dozen intrusions in the first half of 2026 that followed a repeatable seven-step playbook.
The entry point was CVE-2025-5777 (CitrixBleed 2) in Citrix NetScaler ADC/Gateway, which leaks session tokens via malformed pre-auth login requests, bypassing MFA.
In the most advanced case, the attacker deployed DragonForce ransomware.
Source: Huntress