logo

Anubis Ransomware Adds File-Wiping Capability

ID: cc16316e-c14c-5449-907a-c0697700f3ef

STIX ID: report--cc16316e-c14c-5449-907a-c0697700f3ef

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2025-06-16

Date Updated: 2026-04-22

...
...

Trend Micro researchers identified Anubis, an emerging RaaS active since December 2024, which pairs standard encryption and data theft with a destructive "wipe mode" that permanently erases files (using commands like vssadmin delete shadows and a /WIPEMODE parameter). The operator advertises flexible affiliate programs (including access monetization and data-only options), has listed seven victims across multiple industries and countries on its leak site, and typically gains initial access via spear-phishing, increasing pressure on victims and complicating recovery efforts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.