logo

Ransomware Tracker (Entry #215): Anonymous

ID: 1d006e38-725e-5ace-aa8a-de8ed81f461e

STIX ID: report--1d006e38-725e-5ace-aa8a-de8ed81f461e

Feed Name: WatchGuard Secplicity Blog

Threat Score
70/100

Date Published: 2025-02-24

Date Updated: 2026-05-01

Author: Ryan Estes

...
...

The report analyzes an 'Anonymous' ransomware sample derived from the NoCry/WannaCry builder and likely an early AzzaSec variant: it encrypts files with AES (appending .Anonymous), alters the desktop and shows a ransom modal, and drops an HTML ransom note. The sample shares many indicators with the XRed Backdoor—domains, hosted payload URLs (Google Drive/Dropbox links and site50.net paths) and actor email addresses—and XRed reportedly uses SMTP to exfiltrate system information, indicating related tooling and an operational risk to affected systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.