Ransomware Starts at the Gateway, Not the Endpoint

Anubis matters because it turns internet-facing access gear into the first step of a ransomware case. The standard endpoint-first response misses the real break: if a NetScaler gateway is exposed, the attacker can get in before any file encryption starts, and patching later does not undo that foothold. Fortra ties Anubis to exploitation of CVE-2025-5777 on Citrix NetScaler, which keeps the issue squarely on Gateway and ADC appliances used for VPN, ICA Proxy, CVPN, RDP Proxy, and AAA virtual servers. Fortra also says the group runs as ransomware-as-a-service and can use an optional wipe mode that zeroes files instead of just encrypting them, which makes recovery much harder when backups are weak or absent. The risk now is broader than one malware family. A vulnerable remote-access appliance can open the path into the rest of the network, and an overdue KEV plus very high EPSS means some of those perimeter boxes are still likely to be reachable entry points.

Part of the PlainSec briefing for 2026-07-17

Sources