Last seven days
- First activity
- Jul 16, 2026
- Last activity
- Jul 16, 2026
- Feed role
- C2
- Host form
- 1 IP / 3 hostnames
Anubis is a ransomware-as-a-service operation that emerged in late 2024 after rebranding from Sphinx.
Profile source: Mallory opens in a new tabAnubis
Anubis is a ransomware-as-a-service operation that emerged in late 2024 after rebranding from Sphinx. It operates through affiliates and has targeted organizations across multiple sectors, including healthcare, manufacturing, construction, legal services, financial services, business services, and technology, with a large share of claimed victims in the United States. The malware supports data-theft-and-encryption extortion and has been reported to include an optional destructive wipe capability that can reduce victim files to zero-byte content, increasing coercive pressure beyond conventional ransomware encryption.
Observed Anubis intrusions in 2026 show a practical, affiliate-driven tradecraft model rather than reliance on a single distinctive malware component. Initial access has been associated with spearphishing, use of valid VPN credentials, and exploitation of CitrixBleed 2 (CVE-2025-5777) against Citrix NetScaler infrastructure. Post-compromise activity has included session hijacking opportunities tied to exposed session material, credential access, lateral movement over RDP and SMB, PsExec-based remote execution, deployment of legitimate remote monitoring and management tools, tunneling utilities, cloud-transfer tools, and other living-off-the-land techniques intended to blend with normal administrative activity. Affiliates have also been observed weakening security visibility and tampering with endpoint protections before encryption.
The ransomware has been described as targeting Windows, Linux, NAS, and ESXi environments, with reported privilege escalation to SYSTEM on Windows and self-propagation of encryption across a domain. Final-stage activity includes file encryption and ransom-note deployment, while pre-encryption phases often involve staging and exfiltration of data. Anubis is therefore best understood as a multi-platform ransomware ecosystem combining initial access, credential abuse, lateral movement, defense evasion, exfiltration, encryption, and optional destructive wiping under an affiliate monetization model.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
In its most recent campaigns, FIN7 has been observed deploying the Python-based Anubis backdoor, which provides full system control via in-memory execution and communicates with its command-and-control infrastructure using Base64-encoded data.
Exploited software
MITRE ATT&CK
Reporting
TRM Labs said it has seen 1VPNS selling its services to ransomware operators for prices ranging from $723 for Anubis to $58 Sinobi.
cet article présente les résultats d’investigations menées tout au long de 2026 sur plusieurs intrusions attribuées au groupe Anubis ransomware, opérant selon un modèle Ransomware-as-a-Service (RaaS).
Hackers linked with Anubis ransomware operation were found abusing the Citrix Bleed 2 (CVE-2025-5777) flaw to find initial access. About Anubis Anubis is a RaaS gang that first surfaced in late 2024 as a spinoff of Sphinx ransomware.
The same pre-encryption lesson applies to other modern ransomware intrusions, including Anubis ransomware abuse of remote-management tools.
Arctic Wolf Labs reported on June 30, 2026 that Anubis ransomware intrusions investigated since the start of 2026 used a mix of valid VPN credentials, exploitation of CitrixBleed 2, RDP movement, credential access, remote management software, tunnels, and cloud-transfer utilities before encryption.
Since the start of 2026, Arctic Wolf has investigated Anubis ransomware intrusions involving both valid VPN credential use and exploitation of CitrixBleed 2 (CVE-2025-5777), expanding known initial access tradecraft associated with this ransomware brand.
Anubis stands apart from all other top-20 actors in its willingness to target healthcare (13.0%, +8.3 percentage points above baseline) and critical infrastructure (8.7%, +7.7 percentage points above baseline).
ANUBIS is a ransomware operation targeting mid-sized organizations using encryption-based payloads and extortion tactics.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.