CVE-2025-5777, known as Citrix Bleed 2, is being exploited by threat actors to deploy DragonForce ransomware. Attackers follow a consistent post-compromise pattern including privilege escalation, creation of rogue admin accounts, and use of legitimate remote access tools.