Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators CitrixBleed 2 (CVE-2025-5777) 7 Steps to Dragonforce Ransomware

relay.dltsolutions.top

TLP:CLEAR
Active

Domain

Description

Between January and June 2026, multiple unrelated organizations experienced nearly identical intrusions following a standardized seven-step attack chain. The attacks exploited CitrixBleed 2 (CVE-2025-5777), a memory-overread vulnerability in NetScaler ADC and Gateway appliances. Attackers sent malformed pre-authentication login requests that leaked NetScaler memory containing valid session tokens, bypassing multi-factor authentication by hijacking active sessions. Following initial access, threat actors consistently escalated privileges to SYSTEM using a registry-symlink exploitation technique targeting the AppMgmt service, created rogue administrator accounts (CtxAppVCOMService, ctxsvc, test), and established persistence through legitimate remote access tools including ScreenConnect and Zoho Assist. The most advanced case culminated in DragonForce ransomware deployment. The highly standardized tradecraft, reused infrastructure, and consistent indicators across unrelated victims sugges...

Sightings (0)

No sightings recorded yet

Details

Name / Label
CitrixBleed 2 (CVE-2025-5777) 7 Steps to Dragonforce Ransomware
Pattern Type
STIX
Confidence
75%
Valid From
Jul 12, 2026 03:07
Total Sightings
0
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of relay.dltsolutions.top

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.