Skip to content

Anubis

Ransomware Group2 claimsLast activity:
Also known as:
  • Sphinx · Rebrand

Overview

Anubis is a financially motivated ransomware-as-a-service operation that emerged in late 2024 from an earlier brand called Sphinx and formally announced its Anubis program in February 2025. Arctic Wolf Labs documented continued Anubis intrusions in 2026 and cautioned that observed tradecraft varies by affiliate. This profile concerns that ransomware operation, not unrelated banking malware or other tools that also use the Anubis name.

Activity and targeting

Anubis operates through affiliates and supports encryption, data theft and post-compromise extortion. Microsoft Security Intelligence describes a multi-vector operation affecting organizations across sectors and geographies rather than a single fixed victim set. Arctic Wolf reported that the operation had evolved into a multi-platform, multi-affiliate ecosystem by 2026, but public leak-site counts and victim claims should not be treated as verified incident totals.

Secureworks Counter Threat Unit research, now published by Sophos, documented advertised restrictions against post-Soviet and BRICS countries and against educational, government and nonprofit organizations. These were criminal-service rules advertised to affiliates, not independently verified proof that every affiliate followed them; the advertisement did not exclude healthcare.

Methods and operational characteristics

The Anubis affiliate program advertised three monetization modes: conventional ransomware with encryption, data-theft-only extortion, and a service for monetizing access that affiliates had already obtained. Secureworks reported that the data-extortion model used password-protected Tor articles, negotiation links, public victim naming and threatened contact with customers and regulators to increase pressure.

Microsoft analyzed a Windows Anubis variant that uses ECIES encryption, appends the .anubis extension, deletes shadow copies, terminates backup, database and security processes, and drops RESTORE FILES ransom notes. The same variant supports an optional /WIPEMODE that overwrites file contents rather than encrypting them, making recovery impossible. The existence of that capability does not establish that wiping occurred in every Anubis incident.

Arctic Wolf’s 2026 incident-response research observed affiliates gaining access through valid VPN credentials and exploitation of CitrixBleed 2, then using RDP, SMB, PsExec, credential access, cloud-transfer tools and legitimate remote-management products. The actors targeted high-value infrastructure including domain controllers, hypervisors, backup-adjacent systems and network-attached storage, while sometimes establishing alternate outbound access through Cloudflare tunnels, proxies or SSH-based tunneling.

What type of group is it?

Anubis is best characterized as a financially motivated ransomware group operating a service and affiliate ecosystem. The core operators advertise infrastructure, extortion support and malware capabilities, while affiliates may choose targets and bring different access methods and tooling; observed behavior should therefore be attributed to Anubis affiliates only when incident-specific evidence supports the link. The reviewed sources do not identify the operators, establish a jurisdiction or support state sponsorship.

Incident claims

Ransomware suspends fairlife U.S. production

View public claim
Incident date: Source: ransomware.livePublished: Discovered:

Claim details

Anubis initially claimed it encrypted fairlife’s Nutanix infrastructure, stole about 1 TB of corporate data and would publish the data unless negotiations began by a July 27 deadline. The Atlanta Business Chronicle later reported that the group was claiming to have released engineering, production and HR material, with alleged files including driver’s-license and salary information. Coca-Cola confirmed that some data was taken but has not verified Anubis attribution, the alleged publication, file authenticity, encryption scope or data volume.

Signature Healthcare cybersecurity incident

View public claim
Incident date: Source: otherPublished: Discovered:

Claim details

Anubis claimed responsibility, alleged theft of 2 TB of patient data and imposed a seven-day payment deadline. Signature Healthcare did not confirm the actor, encryption, data theft, demand amount or payment; the claim remains low confidence.

Impacted organizations

Impacted locations

Sources