STAC3725 is an intrusion cluster first observed in February 2026 and associated with exploitation of CitrixBleed 2 (CVE-2025-5777) against Citrix NetScaler ADC and Gateway environments. The activity has been assessed with high confidence as a highly consistent, productized intrusion runbook, most likely operated by an initial access broker and in at least one case culminating in DragonForce ransomware deployment. The cluster has also been linked to QEMU-based post-compromise tradecraft in which attackers run a hidden Alpine Linux virtual machine on compromised hosts to evade host-based security controls while conducting credential theft and Active Directory operations. The core intrusion pattern begins with pre-authentication exploitation of CitrixBleed 2 to leak session data and hijack already authenticated user sessions, including sessions that had satisfied MFA. After gaining access, the operators commonly escalate privileges on Windows using a portable local privilege-escalation tool that abuses registry symbolic links and the AppMgmt service to obtain SYSTEM privileges. They then create rogue local administrator accounts and establish persistence using legitimate remote management software, most notably malicious ScreenConnect deployments, with Zoho Assist, Netbird, and Atera also observed in overlapping cases. Post-exploitation activity attributed to STAC3725 includes session hijacking, credential theft, privilege escalation, persistence, lateral movement, and defense evasion. Operators have used PsExec, Impacket tooling, Mimikatz, Kerbrute, BloodHound.py, KrbRelayX, Coercer, NetExec, and Metasploit. Observed objectives include harvesting credentials, enumerating Kerberos users, conducting Active Directory reconnaissance, staging data for exfiltration, and preparing follow-on access for other actors. In the most advanced observed intrusion, the activity progressed to DragonForce ransomware execution, supporting the assessment that STAC3725 functions primarily as an access-enablement cluster that can hand off victim environments for ransomware operations rather than acting solely as a single end-stage ransomware crew. Known aliases are limited to STAC3725. No high-confidence nation-state attribution is established. The dominant pattern indicates financially motivated intrusion activity centered on obtaining and monetizing enterprise access.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named activity cluster tracked by Sophos that overlaps with the Citrix NetScaler-to-ransomware intrusion pattern described here and is assessed as likely the same or closely related operation.
An overlapping activity cluster separately tracked by Sophos and mentioned for comparison due to similar Netbird-related tradecraft.
Attack campaign leveraging CitrixBleed2 for initial access, followed by installation of a malicious ScreenConnect client for persistence and deployment of a QEMU VM to conduct credential theft against Active Directory. Attackers manually compile tooling inside the VM for reconnaissance, Kerberos enumeration, coercion, relay, and payload staging.
Campaign using CitrixBleed2 for initial access, then deploying ScreenConnect and QEMU-based virtual machines to conduct reconnaissance, credential theft, persistence, and long-term access operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.