Hackers Abuse CitrixBleed 2 to Steal Session Tokens and Bypass MFA Protections
Hackers are exploiting the CitrixBleed 2 vulnerability to steal active session tokens, bypass multi-factor authentication, and deploy ransomware in targeted Citrix NetScaler environments. Huntress Tac

Hackers are exploiting the CitrixBleed 2 vulnerability to steal active session tokens, bypass multi-factor authentication, and deploy ransomware in targeted Citrix NetScaler environments. Huntress Tactical Response investigated at least six similar incidents between January and June 202620262026, affecting unrelated organizations across multiple sectors. The intrusions consistently began with internet-facing Citrix NetScaler gateways. They progressed through […] The post Hackers Abuse CitrixBleed 2 to Steal Session Tokens and Bypass MFA Protections appeared first on Cyber Security News.
Hackers are exploiting the CitrixBleed 2 vulnerability to steal active session tokens, bypass multi-factor authentication, and deploy ransomware in targeted Citrix NetScaler environments. Huntress Tactical Response investigated at least six similar incidents between January and June 202620262026, affecting unrelated organizations across multiple sectors. The intrusions consistently began with internet-facing Citrix NetScaler gateways. They progressed through privilege escalation, rogue administrator account creation, remote management tool deployment, and, in one confirmed case, the deployment of the DragonForce ransomware. The activity is assessed with high confidence to involve an Initial Access Broker, or possibly a ransomware affiliate, using a repeatable playbook. Sophos has separately tracked related activity under the cluster name STAC3725. CitrixBleed 2 Bypasses MFA The attacks abuse CVE-2025-5777, known as CitrixBleed 2, a pre-authentication memory-overread flaw affecting NetScaler ADC and Gateway devices configured as Gateway or AAA virtual servers. The vulnerability can expose small fragments of appliance memory when attackers submit malformed POST requests to Citrix login endpoints, including /p/u/doAuthentication.do. Specifically, the attacker sends requests with an empty login parameter, causing the appliance to return adjacent memory contents. Citrix NetScaler to Dragonforce Ransomware killchain (Source: huntress) By sending large numbers of requests, attackers can collect heap-memory fragments and search them for active session cookies or tokens. A stolen token allows an attacker to replay an already authenticated user session without knowing the password or completing MFA. Huntress identified nearly 5,9375{,}9375,937 AAA LOGIN_FAILED events from attacker-controlled IP addresses over roughly five hours in one incident. Rather than ordinary failed usernames, the logs contained unprintable binary data, later determined to be leaked NetScaler memory. The strongest evidence of session hijacking appeared when a legitimate user authenticated using LDAP and MFA from a known IP address. Adversary-controlled user executing the LPE application, which relaunches AppMgmt (Source: huntress) Twenty-one minutes later, that same authenticated session was active from an attacker IP address, despite no successful login occurring from that attacker-controlled address. This indicates that MFA protections were not directly broken. Instead, attackers stole and replayed a token from a session where MFA had already been completed. Huntress also found leaked internal IP addresses, HTTP headers, X.509 certificate data, Citrix proxy metadata, and other memory artifacts in the appliance logs. While investigators did not directly recover a session cookie, the malicious request pattern and session activity strongly supported exploitation of CitrixBleed 2. After gaining access via a hijacked Citrix session, attackers often operated as ordinary users. They then used a portable local privilege-escalation tool to obtain NT AUTHORITY\SYSTEM permissions. The unsigned tool was commonly staged under names such as eng.exe, legal.exe, as.exe, or exsym.exe, often delivered in password-protected archives from temp[.]sh. Huntress recovered the archive password as loko123, huntress said. Indicators of Compromise IndicatorTypeDescriptionctxsvcMalicious accountUnauthorized local administrator accountCtxAppVCOMServiceMalicious accountUnauthorized local administrator account Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM. Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google. The post Hackers Abuse CitrixBleed 2 to Steal Session Tokens and Bypass MFA Protections appeared first on Cyber Security News.
Join the Discussion
Comments coming soon. Follow us on social media for real-time discussions.


