Anubis is a ransomware-as-a-service operation that emerged in late 2024 as a rebrand or spinoff of Sphinx ransomware. It is associated with double-extortion activity that combines data exfiltration with file encryption and public leak threats, and it has also advertised or deployed an optional destructive wipe mode that can reduce victim files to zero bytes, increasing pressure on organizations by hindering recovery. The operation has targeted organizations across multiple industries worldwide, with reporting indicating notable impact in sectors including healthcare, manufacturing, construction, legal services, financial services, business services, and technology, and a large share of claimed victims in the United States.
Observed 2026 intrusions attributed to Anubis affiliates show varied tradecraft consistent with an affiliate-driven ecosystem. Reported initial access methods include use of valid VPN credentials, exploitation of CitrixBleed 2 (CVE-2025-5777) against Citrix NetScaler infrastructure, and spearphishing. After access, operators have used legitimate remote management and monitoring tools, remote desktop access, SMB, PsExec, and other living-off-the-land techniques to blend into normal administrative activity, move laterally, harvest credentials, tamper with security controls, stage data for exfiltration, and only later deploy the ransomware payload. Cloud-transfer and tunneling utilities have also been observed during pre-encryption phases.
Anubis is known to append a distinct encrypted-file extension and to drop ransom notes after encryption. The operation has been linked to both Windows and Linux encryption activity in enterprise environments, including attacks affecting virtualized and network-attached storage infrastructure. Its business model reportedly offers affiliates a large share of ransom proceeds, reinforcing its role as a service platform rather than a single intrusion set.
The name Anubis is also used in unrelated malware contexts, including an Android banking trojan and a Python-based backdoor reportedly used by FIN7. In the present context, Anubis refers specifically to the ransomware operation descended from Sphinx, not those separate malware families.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Researchers have identified that common paths of entry involve carefully-crafted spear-phishing emails (with malicious attachments or dangerous links) and - most recently - exploitation of the CitrixBleed 2 (CVE-2025-5777) vulnerability that can expose session tokens and allow attackers to bypass multi-factor authentication (MFA). | The Anubis ransomware-as-a-servie (RaaS) operation first appeared under a different Egyptian-themed name, Sphinx, before rebranding itself in late 2024.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In its most recent campaigns, FIN7 has been observed deploying the Python-based Anubis backdoor, which provides full system control via in-memory execution and communicates with its command-and-control infrastructure using Base64-encoded data.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
Arctic Wolf observed intrusions involving valid VPN credentials and CitrixBleed 2 exploitation against NetScaler ADC and Gateway systems.
Abus d’infrastructure VPN : thème récurrent à travers les intrusions documentées
In at least one intrusion, an Anubis encryptor was deleted after execution, reducing the availability of on-disk payload artifacts for later analysis.
Arctic Wolf observed intrusions involving valid VPN credentials and CitrixBleed 2 exploitation against NetScaler ADC and Gateway systems.
Living-off-the-land : usage de binaires légitimes présents sur les systèmes victimes pour éviter la détection
From there, attackers moved through RDP and SMB, used PsExec service creation, deployed RMM tools, looked for credentials, weakened security visibility, and used cloud-transfer tooling before the final ransomware stage.
Our data shows that the latest version of Anubis has been distributed to 93 different countries and targets the users of 377 variations of financial apps to farm account details. We can also see that, if Anubis successfully runs, an attacker would gain access to contact lists as well as location.
a copy of the Anubis banker Trojan ... intercepts and forwards the credentials for online financial transactions to criminals.
It has a built-in keylogger that can simply steal a users’ account credentials by logging the keystrokes.
In its most recent campaigns, FIN7 has been observed deploying the Python-based Anubis backdoor, which provides full system control via in-memory execution and communicates with its command-and-control infrastructure using Base64-encoded data.
Tunnels and cloud transfer New or unexplained cloudflared , authenticated proxy, SSH SOCKS tunnel... activity on servers.
If the malicious code runs, then the app will try to trick the users into downloading and installing its payload APK with a fake system update.
Хакеры утверждают, что зашифровали инфраструктуру компании и похитили около 1 Тбайт корпоративных данных, которые теперь угрожают опубликовать.
The post also referenced multiple encryption modes, including a "Lite Locker" option and a destructive wipe mode.
suggesting that it had encrypted files on compromised systems | The Anubis ransomware group listed Coca-Cola and Fairlife on its leak website on July 20, suggesting that it had encrypted files on compromised systems
Final ransomware symptoms .anubis file extensions, ransom notes named RESTORE FILES.html or RESTORE FILES.txt , deleted shadow copies, broken restore points...
В 2025 году операторы Anubis добавили в свой арсенал вайпер, который уничтожает файлы жертв и лишает их возможности восстановить данные даже в случае устранения последствий от атаки шифровальщика.
39 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
56 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware used in a double-extortion attack, with operators alleging they stole about 1 TB of data from Fairlife’s systems before encrypting systems and later publishing the stolen data after the leak deadline expired.
Ransomware-as-a-Service platform associated with data theft, file encryption, and an optional file-wiping capability. The content says it emerged in late 2024 as a rebrand of Sphinx.
A ransomware family/group active since December 2024 that uses double extortion by encrypting victim files and exfiltrating data. The content also notes a 'wiper mode' feature that can permanently delete victims’ files and prevent recovery.
Ransomware used in the Fairlife attack; the operators claimed to have encrypted Nutanix systems, stolen roughly one terabyte of files, and threatened public release unless a ransom was paid.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.