logo

New Ransomware Threat Adds File-Wiping Destruction to Encryption Attacks

ID: 5463c1f6-d0e1-5930-9583-cf476bd0b3ca

STIX ID: report--5463c1f6-d0e1-5930-9583-cf476bd0b3ca

Feed Name: Halcyon Blog

Threat Score
75/100

Date Published: 2025-06-23

Date Updated: 2026-04-28

...
...

Researchers have identified a new RaaS called Anubis that augments the double-extortion model with a custom file wiper (WIPEMODE) enabling attackers to permanently destroy data in addition to stealing and encrypting it; the malware is delivered via phishing, command-line execution and privilege escalation, and defenders are advised to maintain secure offline/off-site backups, limit admin privileges, and keep security controls updated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.