logo

Anubis Ransomware Targets Global Victims with Wiper Functionality

ID: 493ef07b-65a1-5934-8866-16417c23627a

STIX ID: report--493ef07b-65a1-5934-8866-16417c23627a

Feed Name: Resources-2

Threat Score
80/100

Date Published: 2025-06-27

Date Updated: 2026-07-22

Author: [email protected] (Sıla Özeren)

...
...

Anubis is a Ransomware-as-a-Service observed since December 2024 that combines ECIES-based file encryption with an optional file‑wiping module and double-extortion tactics. The report maps Anubis behavior to MITRE ATT&CK (initial access via spearphishing, command/script execution, token manipulation, shadow copy deletion, service termination), provides sample hashes and process/service IoCs, and discusses prevention and simulation guidance for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.