logo

Dark Web Profile: Anubis Ransomware

ID: fcedf491-4b5b-54aa-96ca-5997228a7a12

STIX ID: report--fcedf491-4b5b-54aa-96ca-5997228a7a12

Feed Name: SOCRadar Blog

Threat Score
75/100

Date Published: 2026-01-22

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

Anubis (aka Sphinx) is a Ransomware-as-a-Service (RaaS) operation first observed in late 2024 that emphasizes targeted, manual intrusions by affiliates and offers both file encryption and an optional destructive wipe mode that makes recovery impossible; it also monetizes intrusions through data extortion and access resale. The report details its affiliate-driven model, initial-access methods (spear-phishing, exposed RDP, trojanized installers), execution and privilege escalation behaviors, defense-evasion and backup-destruction techniques, MITRE mappings, and mitigation guidance focused on reducing exposure, hardening backups, detecting pre-encryption activity, and prioritizing patching and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.