Storm-2570 defense-evasion tactics were observed across ransomware intrusions involving Qilin, DragonForce, and Anubis deployment.
Anubis
Anubis is an ambiguous malware label used for distinct Android banking-malware and ransomware operations.
Profile source: Mallory opens in a new tabAnubis
Family profile
Anubis is an ambiguous malware label used for distinct Android banking-malware and ransomware operations. The Android Anubis banking trojan has been distributed through phishing links and trojanized applications, including COVID-19-themed contact-tracing lures. It masquerades as trusted Android software, requests accessibility permissions, identifies targeted installed applications, uses credential-stealing overlays, captures keystrokes, and can access SMS messages, contacts, audio, phone calls, and locally stored files. A separate Anubis ransomware-as-a-service operation emerged in 2025. This operation combines file encryption and data-leak extortion with an optional wiping mode that permanently removes file contents to hinder recovery. It has been assessed to use spear-phishing for initial access, delete volume shadow copies, stop services and processes, encrypt data using ECIES-based cryptography, and threaten publication of stolen data. Its affiliate program has advertised ransomware, data-extortion, and access-monetization arrangements, and reported victims have included organizations in healthcare, engineering, and construction.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Extortion
- Keylogging
- Lateral Movement
- Privilege Escalation
- Reconnaissance
Reported operators
Threat actors
2 named in public reportingIn its most recent campaigns, FIN7 has been observed deploying the Python-based Anubis backdoor, which provides full system control via in-memory execution and communicates with its command-and-control infrastructure using Base64-encoded data.
Exploited software
Vulnerabilities linked to Anubis
2 CVEsMITRE ATT&CK
Anubis in ATT&CK
75 distinct techniquesTechniques
75 techniquesReporting
Research mentioning Anubis
July was the worst month for ransomware victim claims in 2026 - or was it? | ZDNET
Security reporting has documented LameHug as the first publicly known malware to integrate a large language model, marking an escalation in the use of generative AI within malicious tooling. The development indicates that AI can be incorporated into malware operations rather than being used solely to create phishing content or assist attackers outside the payload. Separately, ransomware victim listings reached 894 organizations in July 2026, according to NCC Group data cited by ZDNET, with industrial organizations comprising nearly one-third of listed victims. The reporting also identified the first documented fully agentic AI ransomware attack chain, attributed to JadePuffer, amid a surge led by groups including The Gentlemen and Qilin; however, organizations should treat leak-site claims cautiously because some actors, including the new CRPxO RaaS operation, may inflate or fabricate victim listings.
500 Hosts, 1 TB and No Negotiation: Anubis Provides Details on the Fairlife Attack - Malware News - Malware Analysis, News and Indicators
The Anubis ransomware group claimed it compromised dairy producer Fairlife, affecting 500 hosts and stealing about 1 TB of data, according to reporting that also highlighted differences between the gang’s account and statements attributed to parent company Coca-Cola. Anubis said the intrusion was opportunistic rather than targeted, describing its method as opening “all doors with weak locks” before determining what it had accessed. Anubis further claimed there was no real negotiation after the intrusion, saying it waited just over a week, attempted to contact the victim by telephone, and then deleted the decryption keys before starting to publish stolen data when no response arrived. The reporting underscores how quickly ransomware operators now move from intrusion to extortion and public leaks, compressing the timeline for incident response, executive decision-making, and disclosure.
500 Hosts, 1 TB and No Negotiation: Anubis Provides Details on the Fairlife Attack - DataBreaches.Net
Операторы вымогателя Anubis взяли на себя ответственность за взлом дочернего предприятия Coca-Cola - Хакер
The Coca-Cola Company disclosed in an SEC filing that a ransomware attack hit systems at its wholly owned dairy subsidiary Fairlife, giving attackers unauthorized access to part of the company’s environment, including production-related systems. The incident forced Fairlife to temporarily suspend production of its products across U.S. facilities, while the company said Canadian operations were not affected and that product quality and safety were not impacted. Coca-Cola said it activated incident response and business continuity procedures, engaged outside advisors and cybersecurity experts, and notified law enforcement as it investigates the full scope and business impact of the breach. The company has not said whether data was stolen, whether an extortion demand was made, or when U.S. production will resume, and no ransomware group had publicly claimed responsibility at the time of reporting.