Dark Web Profile: Anubis Ransomware
ID: fcedf491-4b5b-54aa-96ca-5997228a7a12
STIX ID: report--fcedf491-4b5b-54aa-96ca-5997228a7a12
Feed Name: SOCRadar Blog
Anubis (aka Sphinx) is a Ransomware-as-a-Service (RaaS) operation first observed in late 2024 that emphasizes targeted, manual intrusions by affiliates and offers both file encryption and an optional destructive wipe mode that makes recovery impossible; it also monetizes intrusions through data extortion and access resale. The report details its affiliate-driven model, initial-access methods (spear-phishing, exposed RDP, trojanized installers), execution and privilege escalation behaviors, defense-evasion and backup-destruction techniques, MITRE mappings, and mitigation guidance focused on reducing exposure, hardening backups, detecting pre-encryption activity, and prioritizing patching and monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
