{
  "Event": {
    "analysis": "1",
    "date": "2026-07-09",
    "extends_uuid": "",
    "info": "[Threat Intel] CitrixBleed 2 (CVE-2025-5777) 7 Steps to Dragonforce Ransomware",
    "protected": false,
    "publish_timestamp": "1784408006",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1784408006",
    "uuid": "972b157d-f197-4dc5-aa1d-11751eb5f434",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#8f20d0",
        "local": false,
        "name": "misp-galaxy:producer=\"Huntress\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#5c57c8",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Windows Service - T1543.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#7d7034",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"",
        "relationship_type": ""
      },
      {
        "colour": "#9feaf0",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exploit Public-Facing Application - T1190\"",
        "relationship_type": ""
      },
      {
        "colour": "#e00500",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Remote Access Tools - T1219\"",
        "relationship_type": ""
      },
      {
        "colour": "#43c8db",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"",
        "relationship_type": ""
      },
      {
        "colour": "#ecc598",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Local Account - T1136.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Clear Windows Event Logs - T1070.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#07ff3c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"LSASS Memory - T1003.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#b76d96",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#59699c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"",
        "relationship_type": ""
      },
      {
        "colour": "#6d779a",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"",
        "relationship_type": ""
      },
      {
        "colour": "#36d931",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"",
        "relationship_type": ""
      },
      {
        "colour": "#0f7a15",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Session Cookie - T1550.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#02475d",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Windows Command Shell - T1059.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#3970d7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Remote System Discovery - T1018\"",
        "relationship_type": ""
      },
      {
        "colour": "#370063",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Remote Desktop Protocol - T1021.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#fae37b",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Service Execution - T1569.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:ransomware=\"dragonforce\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#120044",
        "local": false,
        "name": "rectifyq:sub-category=\"intrusion-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#130049",
        "local": false,
        "name": "rectifyq:sub-category=\"campaign-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#d92121",
        "local": false,
        "name": "rectifyq:target=\"targeted\"",
        "relationship_type": ""
      },
      {
        "colour": "#170057",
        "local": false,
        "name": "rectifyq:sub-category=\"critical-vuln\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:malpedia=\"MimiKatz\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:malpedia=\"RemCom\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:rmm-tool=\"Atera\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:rmm-tool=\"NetBird\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:rmm-tool=\"PSEXEC\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:rmm-tool=\"ScreenConnect\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:rmm-tool=\"Zoho Assist\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:tool=\"IMPACKET\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783681231",
        "to_ids": false,
        "type": "link",
        "uuid": "ce2eef1c-f67c-409f-9a87-baba7b34ec02",
        "value": "https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783681231",
        "to_ids": false,
        "type": "text",
        "uuid": "d99bfe1f-4e4e-409b-8ccf-29894200b678",
        "value": "Between January and June 2026, multiple unrelated organizations experienced nearly identical intrusions following a standardized seven-step attack chain. The attacks exploited CitrixBleed 2 (CVE-2025-5777), a memory-overread vulnerability in NetScaler ADC and Gateway appliances. Attackers sent malformed pre-authentication login requests that leaked NetScaler memory containing valid session tokens, bypassing multi-factor authentication by hijacking active sessions. Following initial access, threat actors consistently escalated privileges to SYSTEM using a registry-symlink exploitation technique targeting the AppMgmt service, created rogue administrator accounts (CtxAppVCOMService, ctxsvc, test), and established persistence through legitimate remote access tools including ScreenConnect and Zoho Assist. The most advanced case culminated in DragonForce ransomware deployment. The highly standardized tradecraft, reused infrastructure, and consistent indicators across unrelated victims suggest a single Initial Ac..."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783681231",
        "to_ids": false,
        "type": "text",
        "uuid": "319444b4-26b0-4f9d-ada0-fa3e68e66aa4",
        "value": "Name: CitrixBleed 2 (CVE-2025-5777) 7 Steps to Dragonforce Ransomware\nAuthor: AlienVault\nAdversary: DragonForce\nTags: [\"cve-2025-5777\", \"mimikatz\", \"screenconnect\", \"initial access broker\", \"impacket\", \"citrixbleed 2\", \"dragonforce\", \"session hijacking\", \"privilege escalation\", \"netscaler\", \"ransomware\"]\nTgtd countries: []\nMlwr families: [\"DragonForce\", \"Mimikatz\", \"Impacket\"]\nAttack_ids: [\"T1543.003\", \"T1082\", \"T1190\", \"T1219\", \"T1055\", \"T1136.001\", \"T1070.001\", \"T1003.001\", \"T1547.001\", \"T1078\", \"T1068\", \"T1486\", \"T1550.004\", \"T1059.003\", \"T1018\", \"T1021.001\", \"T1569.002\"]\nIndustries: []"
      },
      {
        "category": "Attribution",
        "comment": "Adversary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783681231",
        "to_ids": false,
        "type": "threat-actor",
        "uuid": "5d06adcf-a46a-4474-8f8d-ca61ea5de8fe",
        "value": "DragonForce"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783681231",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "83e68261-6022-4b05-825d-c51acbbd7255",
        "value": "CVE-2017-18362"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783681231",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "7317c6cb-f026-466f-afb1-51613e41aefb",
        "value": "CVE-2023-4966"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783681231",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "4c0b9dfb-aab4-4f0a-9616-f04b897da0a2",
        "value": "CVE-2025-5777"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784379333",
        "to_ids": true,
        "type": "domain",
        "uuid": "88051f5d-1996-4ff8-ac0f-1ea75f555317",
        "value": "doauthentication.do",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783681231",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "b4443f82-10a4-450f-9327-230f6d287886",
        "value": "CVE-2026-4368"
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check: 18/07/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784407986",
        "to_ids": true,
        "type": "sha256",
        "uuid": "ff7f9bd8-cd31-4126-90b6-e5f0514def65",
        "value": "c4fcae3847946173bf0b3cedf5d97a9e3d18090023842f942ba544fa7fda180d",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check: 18/07/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784408004",
        "to_ids": true,
        "type": "sha256",
        "uuid": "65df5623-9283-4dff-a6d2-766a7c38e461",
        "value": "c84739655ce1af0a0269138263d47567418f69e0f75e249f8e23bc21802209e2",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check: 18/07/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784408006",
        "to_ids": true,
        "type": "sha256",
        "uuid": "d368e0fa-875d-47bc-a4c5-fcbbcd8dec4c",
        "value": "eb083365dc70d0294e8c4f55a2e78be0edb0f3497f2a06a70c9f474dafab48d8",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784379355",
        "to_ids": true,
        "type": "url",
        "uuid": "dba9f9c8-4639-4376-a150-ff25a731e57d",
        "value": "http://relay.eurofin.digital:8041",
        "Tag": [
          {
            "colour": "#f08989",
            "local": false,
            "name": "NotFoundError",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784379376",
        "to_ids": true,
        "type": "domain",
        "uuid": "5cd5e1de-de63-4f78-b3aa-151aa24a4b2c",
        "value": "vpts.us",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784379397",
        "to_ids": true,
        "type": "hostname",
        "uuid": "2a5435a5-4cae-404f-b775-49a070c67639",
        "value": "opa.tlsd.shop",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784379418",
        "to_ids": true,
        "type": "hostname",
        "uuid": "19f4621e-402c-4002-bba8-d47a9c2b989a",
        "value": "relay.dltsolutions.top",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784379439",
        "to_ids": true,
        "type": "hostname",
        "uuid": "cfb2b5cf-b2d4-4ed8-bdb6-c9f627ea1f4d",
        "value": "relay.eurofin.digital",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784379461",
        "to_ids": true,
        "type": "domain",
        "uuid": "665e2d1f-3405-4797-9dd7-8743a98f00f9",
        "value": "vtps.us",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      }
    ]
  }
}