@Anubis__media
Anubis
Anubis is a ransomware-as-a-service operation that emerged in late 2024 as a rebrand of Sphinx.
Profile source: Mallory opens in a new tabAnubis
Family profile
Anubis is a ransomware-as-a-service operation that emerged in late 2024 as a rebrand of Sphinx. It is a double-extortion ransomware family whose affiliates steal data prior to encryption and threaten public release to coerce payment. Reporting from 2026 also attributes to Anubis an optional destructive wipe capability that can reduce victim files to zero bytes, increasing pressure by impeding recovery even after incident response actions. The malware has been observed appending an Anubis-specific encrypted-file extension and deploying ransom notes after encryption.
Anubis intrusions in 2026 showed affiliate-driven tradecraft rather than a single uniform playbook. Initial access has been associated with spearphishing, use of valid VPN credentials, and exploitation of internet-facing systems, including CitrixBleed 2 (CVE-2025-5777). Post-compromise activity commonly includes credential access, abuse of legitimate remote monitoring and management tools, lateral movement over RDP and SMB, PsExec-based remote execution, tunneling, cloud-transfer tooling, and attempts to weaken security visibility before the final encryption stage. The operation has also been linked to exploitation of exposed VPN and public-facing enterprise services.
Victimology spans multiple sectors worldwide, including healthcare, manufacturing, construction, engineering, legal, financial services, and maritime infrastructure, with a large share of claimed victims in the United States. Publicly reported incidents tied to Anubis have included disruptive attacks against healthcare providers, manufacturing operations, and port infrastructure, demonstrating both data-theft extortion and operational disruption. Anubis is unrelated to the older Android banking trojan of the same name.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Extortion
- Lateral Movement
- Persistence
Operational record
Published indicators
Md5
25 totala1765503f1405b24b77a16071e6ea6f6d2410703e93be61a652b92efcf42789d0a5f3fc92af7aa3e448ac7b84e495fc6271998018494403a9b5d0d4b01eb0c448a12e997e672b80319c5b852b237e5a9f71d8db7fda7659718330efcbd0776f00f1b8aa83e5f9c40ad32561a95ed2c6771ce395e8bb531ec3623b94387de8392284d536dab5865150873e927a29cb0aea4b88bf440613390cd32e045a59fd7b0
Ip
4 total38.134.148.205.252.177.249212.224.107.203195.133.67.35
Recent claims
Reported operators
Threat actors
1 named in public reportingIn its most recent campaigns, FIN7 has been observed deploying the Python-based Anubis backdoor, which provides full system control via in-memory execution and communicates with its command-and-control infrastructure using Base64-encoded data.
Exploited software
Vulnerabilities linked to Anubis
2 CVEsMITRE ATT&CK
Anubis in ATT&CK
46 distinct techniquesTechniques
46 techniquesReporting
Research mentioning Anubis
Операторы вымогателя Anubis взяли на себя ответственность за взлом дочернего предприятия Coca-Cola - Хакер
The Coca-Cola Company disclosed in an SEC filing that a ransomware attack hit systems at its wholly owned dairy subsidiary Fairlife, giving attackers unauthorized access to part of the company’s environment, including production-related systems. The incident forced Fairlife to temporarily suspend production of its products across U.S. facilities, while the company said Canadian operations were not affected and that product quality and safety were not impacted. Coca-Cola said it activated incident response and business continuity procedures, engaged outside advisors and cybersecurity experts, and notified law enforcement as it investigates the full scope and business impact of the breach. The company has not said whether data was stolen, whether an extortion demand was made, or when U.S. production will resume, and no ransomware group had publicly claimed responsibility at the time of reporting.