Alex Yao Alex Yao
Back to news
Cyber Security Published on July 9, 2026

Initial access broker weaponizes CitrixBleed 2 to deploy DragonForce ransomware

Huntress investigated roughly half a dozen intrusions in the first half of 2026 that followed a repeatable seven-step playbook.

The entry point was CVE-2025-5777 (CitrixBleed 2) in Citrix NetScaler ADC/Gateway, which leaks session tokens via malformed pre-auth login requests, bypassing MFA.

In the most advanced case, the attacker deployed DragonForce ransomware.

Source: Huntress