Anubis is a ransomware-as-a-service operation that emerged in late 2024 as a rebrand of Sphinx. It is used by affiliates to conduct double-extortion attacks that combine data exfiltration with file encryption, and later versions added an optional destructive wipe capability that can permanently zero out victim files to increase coercive pressure and hinder recovery. Encrypted files are associated with the .anubis extension, and the malware has been observed on both Windows and Linux environments.
Observed Anubis intrusions in 2026 show affiliate-driven tradecraft rather than a single uniform playbook. Initial access has been linked at high confidence to exploitation of CitrixBleed 2 (CVE-2025-5777) against Citrix NetScaler infrastructure and to the use of valid VPN credentials. After access, operators commonly perform credential harvesting, lateral movement over RDP and SMB, PsExec-based remote execution, deployment of legitimate remote monitoring and management tools, tunneling, cloud-transfer activity, and security-control tampering before launching encryption. Reported tooling patterns include abuse of remote administration software to blend into normal IT operations and support hands-on-keyboard post-compromise activity.
Anubis has targeted organizations across multiple sectors worldwide, with reporting indicating notable activity against healthcare, manufacturing, financial services, legal services, construction, business services, and technology organizations. Victimology has shown a strong concentration in the United States, followed by other English-speaking and Western countries. Publicly claimed incidents include disruptive attacks affecting manufacturing operations, illustrating that Anubis activity can impact business continuity as well as confidentiality.
The operation is run as an affiliate program and has been described as offering a high revenue share to partners. Its tradecraft emphasizes stealthy pre-encryption staging, credential access, exfiltration, and defense evasion, making it more than a simple encryptor. Anubis should be understood as a mature RaaS ecosystem whose affiliates combine conventional ransomware deployment with enterprise intrusion techniques and, in some cases, destructive file wiping.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Researchers have identified that common paths of entry involve carefully-crafted spear-phishing emails (with malicious attachments or dangerous links) and - most recently - exploitation of the CitrixBleed 2 (CVE-2025-5777) vulnerability that can expose session tokens and allow attackers to bypass multi-factor authentication (MFA). | The Anubis ransomware-as-a-servie (RaaS) operation first appeared under a different Egyptian-themed name, Sphinx, before rebranding itself in late 2024.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In its most recent campaigns, FIN7 has been observed deploying the Python-based Anubis backdoor, which provides full system control via in-memory execution and communicates with its command-and-control infrastructure using Base64-encoded data.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
Arctic Wolf observed intrusions involving valid VPN credentials and CitrixBleed 2 exploitation against NetScaler ADC and Gateway systems.
Abus d’infrastructure VPN : thème récurrent à travers les intrusions documentées
In at least one intrusion, an Anubis encryptor was deleted after execution, reducing the availability of on-disk payload artifacts for later analysis.
Arctic Wolf observed intrusions involving valid VPN credentials and CitrixBleed 2 exploitation against NetScaler ADC and Gateway systems.
Living-off-the-land : usage de binaires légitimes présents sur les systèmes victimes pour éviter la détection
From there, attackers moved through RDP and SMB, used PsExec service creation, deployed RMM tools, looked for credentials, weakened security visibility, and used cloud-transfer tooling before the final ransomware stage.
Our data shows that the latest version of Anubis has been distributed to 93 different countries and targets the users of 377 variations of financial apps to farm account details. We can also see that, if Anubis successfully runs, an attacker would gain access to contact lists as well as location.
a copy of the Anubis banker Trojan ... intercepts and forwards the credentials for online financial transactions to criminals.
It has a built-in keylogger that can simply steal a users’ account credentials by logging the keystrokes.
In its most recent campaigns, FIN7 has been observed deploying the Python-based Anubis backdoor, which provides full system control via in-memory execution and communicates with its command-and-control infrastructure using Base64-encoded data.
Tunnels and cloud transfer New or unexplained cloudflared , authenticated proxy, SSH SOCKS tunnel... activity on servers.
If the malicious code runs, then the app will try to trick the users into downloading and installing its payload APK with a fake system update.
Хакеры утверждают, что зашифровали инфраструктуру компании и похитили около 1 Тбайт корпоративных данных, которые теперь угрожают опубликовать.
The post also referenced multiple encryption modes, including a "Lite Locker" option and a destructive wipe mode.
suggesting that it had encrypted files on compromised systems | The Anubis ransomware group listed Coca-Cola and Fairlife on its leak website on July 20, suggesting that it had encrypted files on compromised systems
Final ransomware symptoms .anubis file extensions, ransom notes named RESTORE FILES.html or RESTORE FILES.txt , deleted shadow copies, broken restore points...
В 2025 году операторы Anubis добавили в свой арсенал вайпер, который уничтожает файлы жертв и лишает их возможности восстановить данные даже в случае устранения последствий от атаки шифровальщика.
39 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
58 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as another ransomware example with a similar RMM-to-encryption pattern.
Ransomware used in an attack against fairlife that allegedly involved data theft and extortion, with attackers threatening to leak stolen data unless payment was made.
Ransomware used in a double-extortion attack, with operators alleging they stole about 1 TB of data from Fairlife’s systems before encrypting systems and later publishing the stolen data after the leak deadline expired.
Ransomware-as-a-Service platform associated with data theft, file encryption, and an optional file-wiping capability. The content says it emerged in late 2024 as a rebrand of Sphinx.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.