Skip to content

Anubis

Anubis is a ransomware-as-a-service operation that emerged in late 2024 as a rebrand of Sphinx.

Profile source: Mallory opens in a new tab

Anubis

Family profile

Anubis is a ransomware-as-a-service operation that emerged in late 2024 as a rebrand of Sphinx. It is a double-extortion ransomware family whose affiliates steal data prior to encryption and threaten public release to coerce payment. Reporting from 2026 also attributes to Anubis an optional destructive wipe capability that can reduce victim files to zero bytes, increasing pressure by impeding recovery even after incident response actions. The malware has been observed appending an Anubis-specific encrypted-file extension and deploying ransom notes after encryption.

Anubis intrusions in 2026 showed affiliate-driven tradecraft rather than a single uniform playbook. Initial access has been associated with spearphishing, use of valid VPN credentials, and exploitation of internet-facing systems, including CitrixBleed 2 (CVE-2025-5777). Post-compromise activity commonly includes credential access, abuse of legitimate remote monitoring and management tools, lateral movement over RDP and SMB, PsExec-based remote execution, tunneling, cloud-transfer tooling, and attempts to weaken security visibility before the final encryption stage. The operation has also been linked to exploitation of exposed VPN and public-facing enterprise services.

Victimology spans multiple sectors worldwide, including healthcare, manufacturing, construction, engineering, legal, financial services, and maritime infrastructure, with a large share of claimed victims in the United States. Publicly reported incidents tied to Anubis have included disruptive attacks against healthcare providers, manufacturing operations, and port infrastructure, demonstrating both data-theft extortion and operational disruption. Anubis is unrelated to the older Android banking trojan of the same name.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Lateral Movement
  • Persistence

Operational record

30
Indicators
1
YARA rules
2
Leak sites
1 available

Published indicators

Twitter

1 total
  • @Anubis__media

Md5

25 total
  • a1765503f1405b24b77a16071e6ea6f6
  • d2410703e93be61a652b92efcf42789d
  • 0a5f3fc92af7aa3e448ac7b84e495fc6
  • 271998018494403a9b5d0d4b01eb0c44
  • 8a12e997e672b80319c5b852b237e5a9
  • f71d8db7fda7659718330efcbd0776f0
  • 0f1b8aa83e5f9c40ad32561a95ed2c67
  • 71ce395e8bb531ec3623b94387de8392
  • 284d536dab5865150873e927a29cb0ae
  • a4b88bf440613390cd32e045a59fd7b0

Ip

4 total
  • 38.134.148.20
  • 5.252.177.249
  • 212.224.107.203
  • 195.133.67.35

Recent claims

Reported operators

Threat actors

1 named in public reporting
FIN7

In its most recent campaigns, FIN7 has been observed deploying the Python-based Anubis backdoor, which provides full system control via in-memory execution and communicates with its command-and-control infrastructure using Base64-encoded data.

Exploited software

Vulnerabilities linked to Anubis

2 CVEs

MITRE ATT&CK

Anubis in ATT&CK

46 distinct techniques

Reporting

Research mentioning Anubis

Jul 23
Xakep

Операторы вымогателя Anubis взяли на себя ответственность за взлом дочернего предприятия Coca-Cola - Хакер

The Coca-Cola Company disclosed in an SEC filing that a ransomware attack hit systems at its wholly owned dairy subsidiary Fairlife, giving attackers unauthorized access to part of the company’s environment, including production-related systems. The incident forced Fairlife to temporarily suspend production of its products across U.S. facilities, while the company said Canadian operations were not affected and that product quality and safety were not impacted. Coca-Cola said it activated incident response and business continuity procedures, engaged outside advisors and cybersecurity experts, and notified law enforcement as it investigates the full scope and business impact of the breach. The company has not said whether data was stolen, whether an extortion demand was made, or when U.S. production will resume, and no ransomware group had publicly claimed responsibility at the time of reporting.

Jul 22
Security Week

Ransomware Group Threatening to Leak Data Stolen From Coca-Cola's Fairlife - SecurityWeek

Jul 22
Cyberthrone

Coca-Cola Fairlife Ransomware Attack - TheCyberThrone

Jul 22
Teiss News

teiss - News - Anubis ransomware gang claims Coca-Cola's Fairlife in data extortion threat

Jul 21
Bleeping Computer

Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak

Jul 21
Securitymagazine

Cyberattack Halts Coca-Cola's Fairlife Productions | Security Magazine

Jul 20
Hookphish

Ransomware Group anubis Hits: Fairlife / Coca-Cola

Jul 20
Cyberveille

Ransomware chez fairlife (Coca-Cola) : production US suspendue | CyberVeille

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.