2026-07-10HIGHexploitedHuntress reconstructs a productised CitrixBleed 2-to-DragonForce runbook: token theft, a registry-symlink SYSTEM escalation, then ransomware
STAC3725 CitrixBleed 2-to-DragonForce IAB chain
campaign · campaign:stac3725-citrixbleed2-iab-dragonforce
Repeatable initial-access-broker kill chain (Sophos: STAC3725): CVE-2025-5777 (CitrixBleed 2) session-token theft on NetScaler Gateway, a registry-symlink/AppMgmt SYSTEM privilege-escalation tool, ScreenConnect/Zoho Assist persistence, and DragonForce ransomware in the most progressed case (Huntress, 2026-07-09; Sophos, 2026-02).
Aliases: CitrixBleed 2 initial-access-broker runbook
Coverage
1
first 2026-07-10 → last 2026-07-10
Latest activity
2026-07-10
Huntress reconstructs a productised CitrixBleed 2-to-DragonForce runbook: token theft, a registry-symlink…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, energy, healthcare
Sources cited
3
3 hosts
Action items (5)
Do-now tasks recorded on the entries about STAC3725 CitrixBleed 2-to-DragonForce IAB chain, newest first. Check the date before acting on an older one.
- Patch every internet-facing NetScaler ADC/Gateway to the fixed build in Citrix's NetScaler security bulletin for CVE-2025-5777 now, and after patching terminate ALL active ICA/PCoIP and AAA sessions; tokens harvested via CVE-2025-5777 remain valid across the patch.2026-07-10CVE-2025-5777
- Hunt NetScaler ns.log for a burst of AAA LOGIN_FAILED events carrying binary/unprintable User values from a single source IP, and for any authenticated session driven from an IP that has no preceding successful authentication.2026-07-10CVE-2025-5777
- Forward NetScaler logs off-box to a SIEM before hunting, on-device ns.log rotates fast enough to lose the evidence.2026-07-10CVE-2025-5777
- Alert on gpupdate followed closely by an AppMgmt (Application Management) service start and a new SYSTEM-context process, and on net user / net localgroup Administrators account creation outside change management.2026-07-10CVE-2025-5777
- Inventory endpoints for unexpected ScreenConnect, Zoho Assist, Netbird or Atera installs not tied to a sanctioned RMM deployment.2026-07-10CVE-2025-5777
Defender insights
What each entry about STAC3725 CitrixBleed 2-to-DragonForce IAB chain tells a defender to do, newest first.
Triage
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
attributed to
Story timeline
Hunting pivots
CVEs (exploited first)
Affected products
ATT&CK techniques (11 across 9 tactics)
11 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- PersistenceAccount Manipulation · Modify Registry · Create Account: Local Account
- Privilege EscalationExploitation for Privilege Escalation · Account Manipulation
- StealthIndicator Removal
- Defense ImpairmentModify Registry
- Credential AccessOS Credential Dumping
- Lateral MovementUse Alternate Authentication Material: Application Access Token · Lateral Tool Transfer
- Command and ControlRemote Access Tools
- ImpactData Encrypted for Impact
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗
Persistence TA0003
T1098Account Manipulation×1
Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.
Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗
T1112Modify Registry×1
Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗
T1136.001Create Account: Local Account×1
Adversaries may create a local account to maintain access to victim systems. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.
Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗
Privilege Escalation TA0004
T1068Exploitation for Privilege Escalation×1
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗
T1098Account Manipulation×1
Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.
Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗
Stealth TA0005
T1070Indicator Removal×1
Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving sufficient data intact to maintain the appearance of normal system behavior.
Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗
Defense Impairment TA0112
T1112Modify Registry×1
Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗
Credential Access TA0006
T1003OS Credential Dumping×1
Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures. Credentials can then be used to perform Lateral Movement and access restricted information.
Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗
Lateral Movement TA0008
T1550.001Use Alternate Authentication Material: Application Access Token×1
Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials.
Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗
T1570Lateral Tool Transfer×1
Adversaries may transfer tools or other files between systems in a compromised environment. Once brought into the victim environment (i.e., Ingress Tool Transfer) files may then be copied from one system to another to stage adversary tools or other files over the course of an operation.
Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗
Command and Control TA0011
T1219Remote Access Tools×1
An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.
Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗
Impact TA0040
T1486Data Encrypted for Impact×1
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
Evidence: 2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725 · ATT&CK page ↗
Entries about STAC3725 CitrixBleed 2-to-DragonForce IAB chain (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Citrix NetScaler×1
- CitrixBleed 2 (NetScaler ADC/Gateway pre-auth memory over-read), weaponised in the STAC3725 IAB-to-DragonForce kill chain (Huntress)×1
- DragonForce×1
Where this entity is cited
Source distribution
- huntress.com1 (33%)
- itsecurityguru.org1 (33%)
- sophos.com1 (33%)
All cited sources (3)
- huntress.comHuntresshttps://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware
- itsecurityguru.orgIT Security Guruhttps://www.itsecurityguru.org/2026/07/09/citrixbleed-2-exploited-in-repeatable-attack-chain-culminating-in-dragonforce-ransomware-researchers-find/
- sophos.comSophos X-Opshttps://www.sophos.com/en-us/blog/qemu-abused-to-evade-detection-and-enable-ransomware-delivery