Ransomware · 60 days ago

Ransomware Starts at the Gateway, Not the Endpoint

Anubis matters because it turns internet-facing access gear into the first step of a ransomware case. The standard endpoint-first response misses the real break: if a NetScaler gateway is exposed, the attacker can get in before any file encryption starts, and patching later does not undo that foothold.

Fortra ties Anubis to exploitation of CVE-2025-5777 on Citrix NetScaler, which keeps the issue squarely on Gateway and ADC appliances used for VPN, ICA Proxy, CVPN, RDP Proxy, and AAA virtual servers. Fortra also says the group runs as ransomware-as-a-service and can use an optional wipe mode that zeroes files instead of just encrypting them, which makes recovery much harder when backups are weak or absent.

The risk now is broader than one malware family. A vulnerable remote-access appliance can open the path into the rest of the network, and an overdue KEV plus very high EPSS means some of those perimeter boxes are still likely to be reachable entry points.

CVE-2025-5777

NVD KEV

Known exploited · CISA KEV

CVSS 7.5 HIGH: insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual… Known ransomware campaign use. EPSS 100% (100th percentile).

CISA federal remediation date Jul 11 · date passed

Timeline

Sources

1 source covering this story

Entities

Vendor digest: Citrix

Part of the PlainSec briefing for 2026-07-17

Editions

Related stories