Anubis + Citrix Bleed 2 + RMM Abuse: NC SMB Remote Access Defense

Anubis ransomware hit 91+ victims via Citrix Bleed 2, ScreenConnect and Cloudflared. NC SMB remote-access defense playbook. Call (336) 886-3282.

Cover Image for Anubis + Citrix Bleed 2 + RMM Abuse: NC SMB Remote Access Defense

TL;DR: Arctic Wolf's July 2026 threat intel and TechTimes' Anubis breach coverage confirm that the Anubis ransomware group has hit at least 91 organizations in 2026 by (a) exploiting Citrix Bleed 2 (CVE-2025-5777) to steal session tokens and bypass MFA, (b) abusing legitimate remote-management tools (ScreenConnect, Zoho Assist, MeshAgent, UltraVNC) to move laterally without triggering AV, and (c) using Cloudflared tunnels to smuggle data out through TLS to Cloudflare IPs. Recent victims include Bath Fitter (July 20) and Coca-Cola-subsidiary Fairlife (Anubis leak-site July 20 following Coke's July 16 SEC 8-K). North Carolina SMBs — especially those on MSP-delivered RMM tools and NetScaler ADC appliances — need a same-week remote-access audit.

Key takeaway: The 2026 ransomware wave does not need novel malware. It uses your Citrix appliance, your MSP's RMM tool, and Cloudflare's tunnel product against you. The defense is not "buy more AV," it is inventory + patch + allowlist RMM + monitor outbound tunnels + immutable backup.

Are your NetScaler, RMM stack, and outbound tunnels audited for Anubis-style abuse? Contact Preferred Data Corporation at (336) 886-3282 for a 72-hour remote-access assessment. Serving High Point, Greensboro, Winston-Salem, Charlotte, Raleigh, and the Piedmont Triad since 1987.

Who Is Anubis and Why Should NC SMBs Care Now?

Anubis is a ransomware-as-a-service operation that emerged in late 2024 and became one of the most prolific SMB-targeting crews of 2026. Fortra's Anubis profile documents an affiliate model with a data-leak site, double-extortion (encrypt + exfiltrate), and a specific preference for small and mid-market victims where MFA gaps and thin monitoring make execution reliable.

Three data points make Anubis a July-2026 NC SMB event rather than a distant enterprise problem.

  • 91-plus victims in the first half of 2026 via Citrix Bleed 2 alone, covering healthcare, manufacturing, technology, business services, and financial services.
  • US-heavy victimologyDeXpose's Bath Fitter attack analysis confirms US SMBs and mid-market firms as the bulk of Anubis' book, with 50%+ of victims in the United States.
  • RMM-abuse pattern — the Anubis playbook systematically weaponizes tools an MSP would install for legitimate remote support, so the exfiltration and lateral movement look identical to normal IT activity in a small SOC.

For a Triad manufacturer, a Charlotte medical practice, or a Wilmington law firm, "identical to normal IT activity" is exactly the pattern that a Defender-only stack, an IT-outsourced-to-a-two-person MSP, or a bank-hours SOC will miss.

What Is Citrix Bleed 2 (CVE-2025-5777) and Why Is It Still Exploited in Mid-2026?

Citrix Bleed 2 is an out-of-bounds read vulnerability in Citrix NetScaler ADC and NetScaler Gateway that lets an unauthenticated attacker read chunks of process memory over HTTP. In practice, that memory contains active session tokens for authenticated users, which an attacker can lift and replay to enter the environment as a valid, MFA-satisfied user. It is a modern re-run of the 2023 Citrix Bleed pattern — The Hacker News' July 2026 ransomware roundup documents the pivot to Citrix Bleed 2 as a preferred initial-access vector across multiple ransomware crews, not just Anubis.

Three defensive points matter for NC SMBs.

  • MFA does not stop Citrix Bleed 2, because the stolen token has already satisfied MFA at the point of theft. This is why "we have MFA" is not a defense against session-hijacking attacks in 2026.
  • Patching alone is not enough, because tokens issued during the exposure window remain valid until they expire. Post-patch, defenders must invalidate all active sessions and force reauthentication.
  • NetScaler appliances often live in the DMZ of small businesses because they were installed years ago for VPN or remote-app publishing and are treated as "networking gear" rather than as attack surface. Every NC SMB with an on-prem NetScaler should confirm patch build and forcibly clear all sessions this week.

How Do Anubis Affiliates Abuse RMM and Cloudflared to Stay Invisible?

The Anubis affiliate playbook is a textbook example of living-off-the-land attacks — using legitimate, signed, whitelisted tools to accomplish adversary objectives. Arctic Wolf documents four RMM-tool abuse patterns and one exfiltration pattern that recur across Anubis victims.

  • ScreenConnect and Zoho Assist installed post-compromise as a "second door" that persists even after the original access is closed. Both are legitimate IT tools whose installers are trusted by most AV.
  • MeshAgent and UltraVNC deployed as backup persistence, so removing ScreenConnect does not remove attacker access.
  • Remotely and Total Software Deployment used for mass push of the ransomware payload, mimicking a normal software-deployment task.
  • Legitimate MSP tooling reused — when Anubis compromises an MSP or a vendor with cross-tenant credentials, it can push tooling through the MSP's real RMM to multiple downstream SMB tenants at once.
  • Cloudflared tunnels for exfiltration — Cloudflare's cloudflared binary is downloaded to the victim, an outbound tunnel is established to a Cloudflare-hosted attacker endpoint, and terabytes of data flow out over TLS to a Cloudflare IP that no NC SMB firewall would block.

The single most important operational implication is that detecting Anubis by looking for "unusual software" almost always fails, because none of the software is unusual. Detection requires looking at behavior: which user account installed ScreenConnect, from where, at what time, and whether the outbound Cloudflared tunnel matches any known-good pattern for the business.

What Do Bath Fitter, Fairlife, and Other July 2026 Anubis Victims Tell Us?

Two recent Anubis victims illustrate the SMB relevance for NC business owners. DeXpose's Bath Fitter analysis reports the July 20, 2026 posting of Bath Fitter — a US manufacturing company with ~600 franchisees — on Anubis' leak site, with data-exfiltration claims and a public ransom demand. SecurityWeek's Anubis-Fairlife reporting covers the July 20 Anubis leak of Fairlife, following Coca-Cola's July 16 SEC 8-K disclosure of the underlying incident.

Three lessons transfer directly to NC SMBs.

  • Franchise, dealer, and multi-location structures amplify blast radius. Bath Fitter's franchise footprint means the compromise touches hundreds of independent small-business owners. Any NC business with a similar franchise or dealer network should assume a single compromise cascades.
  • Manufacturing supply chains are Anubis' bread and butter. Help Net Security's mid-July ransomware trends report puts manufacturing as the most targeted sector in the first half of 2026. NC has 350+ defense manufacturers plus thousands of small industrial and food-manufacturing firms in the Piedmont Triad.
  • Public-company subsidiaries pull SMB suppliers into the disclosure timeline. When a large parent (Coca-Cola) files an 8-K, downstream suppliers get pulled into the notification and evidence-request process within 72 hours. Any NC SMB that supplies a public company should have a documented incident-response evidence packet ready to hand over on 24-hour notice.

What Does a 30-Day NC SMB Anubis-Style Defense Program Look Like?

A 30-day program that hardens against the Anubis playbook can be executed by a competent internal IT team or by a managed provider like PDC's managed cybersecurity practice. The program has four parallel workstreams.

  • Workstream 1: Identity + session hygiene. Force-reset all active NetScaler sessions after applying the CVE-2025-5777 patch. Enable session-binding to source IP where the client base is small. Enforce phishing-resistant MFA (FIDO2, Windows Hello for Business) for admin accounts. Move all admin activity to a Privileged Access Workstation.
  • Workstream 2: RMM inventory and allowlist. Enumerate every installed RMM agent across the fleet (ScreenConnect, Zoho Assist, MeshAgent, UltraVNC, Splashtop, TeamViewer, N-able, ConnectWise Automate, Datto RMM, Kaseya VSA). Approved: put on allowlist. Unknown: remove. Any RMM installed by anyone other than the sanctioned IT/MSP account is a red flag.
  • Workstream 3: Outbound tunnel + AiTM detection. Configure DNS filtering, managed detection and response, and firewall egress rules to detect and alert on unusual cloudflared, ngrok, frp, and SSH-tunnel traffic. AiTM (adversary-in-the-middle) phishing kits proxy to real Microsoft 365 or Google Workspace login pages, so an Anubis-style compromise is often bootstrapped through a look-alike-domain sign-in captured via a Cloudflare-hosted reverse proxy.
  • Workstream 4: Backup + IR readiness. Deploy immutable, air-gapped backups with a documented restore test in the last 90 days. Assemble the six-component incident-response packet (technical timeline, forensic image chain-of-custody, executive brief, NC ITPA / HIPAA / DFARS notification templates, insurance broker script, PR statement) so the first response is orderly rather than improvised.

The 30-day plan is not a full security program; it is the specific set of controls that inconveniences the Anubis affiliate model enough to move them to a softer target.

Ready to execute the 30-day Anubis defense plan? Contact Preferred Data Corporation at (336) 886-3282 or visit 1208 Eastchester Drive, Suite 131, High Point, NC 27265.

How Does This Attack Class Compare to Traditional Ransomware Defenses?

Traditional ransomware defense assumes attackers use custom malware, novel exploits, and blatant activity. Modern Anubis-style attacks assume the opposite: legitimate tools, patched-but-not-invalidated sessions, quiet lateral movement.

Defensive LayerTraditional Ransomware ValueAnubis-Style ValueNotes
Signature-based AVMediumLowLOLBins are signed and trusted
Standard MFAHighLowSession-token theft bypasses MFA
Perimeter firewallMediumLowOutbound TLS to Cloudflare bypasses IP filtering
EDR + behavioral detectionHighHighWatches process lineage and network patterns
24/7 MDRHighVery HighOff-hours install + tunnel is the classic Anubis pattern
RMM allowlistingLowVery HighDirect counter to the ScreenConnect/Zoho playbook
Immutable backup + restoreHighHighOnly reliable path to full recovery
Cyber insurance evidence packMediumHighDetermines whether the loss is paid

The gap between "traditional" and "Anubis-style" columns is why NC SMBs still running 2020-vintage ransomware defenses are seeing incidents in 2026 despite MFA and AV. The upgrade path is EDR + 24/7 MDR + RMM allowlist + outbound-tunnel detection + immutable backup, layered on the traditional stack.

How Does Anubis Intersect With NC ITPA, HIPAA, Cyber Insurance, and CMMC?

Any Anubis-style incident against an NC SMB is a five-front event: technical, legal, insurance, PR, and (for regulated data) compliance. Four intersections define the July-2026 playbook.

  • NC ITPA (N.C.G.S. § 75-65). Notification requirements apply to any breach involving NC-resident PII. Anubis double-extortion (encrypt + exfiltrate) usually triggers notification, and the "reasonable security" defense weakens sharply when a known CISA KEV (Citrix Bleed 2) was left unpatched or unrotated.
  • HIPAA and 42 CFR Part 2. For NC healthcare and behavioral-health providers, an Anubis event is a Security Rule Risk Management failing under 45 CFR § 164.308(a)(1)(ii)(B), and HHS OCR's 2026 enforcement expansion applies.
  • CMMC / DFARS 252.204-7012. The July 13, 2026 CMMC Phase 2 pause did not pause the DFARS 7012 72-hour incident-reporting obligation, and NIST SP 800-171 controls remain in force.
  • Cyber insurance. 96% of 2026 policies require MFA and 88% require EDR. An Anubis-style incident that bypassed MFA via session-token theft on an unpatched NetScaler is exactly the fact pattern insurers cite in coverage disputes; a documented Citrix-patch + session-invalidation + RMM-allowlist program is the counter-argument that keeps the claim payable.

Frequently Asked Questions

We do not use Citrix. Are we still exposed to the Anubis playbook?

Yes, partially. Citrix Bleed 2 is one initial-access vector; Anubis also uses phishing, AiTM sign-in proxies, and MSP compromise. The RMM-abuse, tunnel-exfiltration, and lateral-movement stages happen regardless of the initial-access vector. Every NC SMB should harden RMM inventory, outbound-tunnel detection, and immutable backup even without a NetScaler in the environment.

We patched our NetScaler in July. Are we clear?

Not automatically. Tokens issued during the exposure window remain valid until they naturally expire (typically hours). Post-patch, the correct action is to force-invalidate all active sessions, rotate any local admin passwords on the NetScaler, and hunt in NetScaler logs for anomalous session-token use during the exposure window.

How do we tell if ScreenConnect on an endpoint is legitimate or attacker-installed?

The correct check is not "is ScreenConnect installed?" but "who installed it, when, from where, and does it phone home to our sanctioned instance?" A ScreenConnect agent phoning home to an unfamiliar screenconnect.com subdomain or instance ID is a red flag. The PDC managed IT team can build an RMM-allowlist policy that catches this automatically.

Is Cloudflared always malicious?

No. Cloudflare Tunnels have many legitimate uses. The relevant signal is unexpected cloudflared.exe installation, unusual outbound Cloudflare traffic volume, or Cloudflared running from a user profile directory rather than from a Program Files install. Any of those should trigger an investigation.

How much data can an attacker exfiltrate through a Cloudflared tunnel before detection?

Without dedicated egress monitoring, an attacker can exfiltrate essentially unlimited data because Cloudflare IPs are on most firewall allowlists and the traffic is TLS. Realistic case studies show hundreds of gigabytes exfiltrated over 24-48 hours before detection in unmonitored environments. Managed DLP + egress monitoring is the answer.

What does managed detection and response actually catch that Defender misses?

Defender is signature-plus-behavior for a single endpoint. Managed detection and response (MDR) correlates events across endpoints, identity, cloud, and network, and has human analysts on-call 24/7 to interpret ambiguous signals. Anubis-style attacks are specifically designed to look ambiguous, so the human-in-the-loop is where the interruption happens.

What is the cost of a typical Anubis incident for a 50-person NC manufacturer?

Direct ransom demand for a 50-person manufacturer is typically $250K-$2M; direct payout (if paid) is often 25-50% of demand after negotiation. Total loss (downtime, restoration, legal, notification, PR, cyber insurance retention, lost customers) typically runs 3-8x the ransom, so a full incident cost of $1-15M is the honest range. Sophos' 2026 State of Ransomware report supports this range.

Should we ban RMM tools entirely?

No, RMM tools are how modern IT actually gets delivered. The correct posture is a documented approved-tools list, a documented installer-account, and monitoring that alerts on any RMM install by any other account or from any other source. Ban-lists cannot compete with allowlists.

Support