Aliases 

  • Sphinx — original codename under which early ransomware samples and initial victims were recorded in late 2024, before formal rebranding 
  • Anubis__media — operator persona used on the XSS underground forum 
  • superSonic — operator persona used on the RAMP underground forum for affiliate recruitment 

 

Get Threat Intel and Security Updates Delivered to Your Inbox.

 

Profiling 

Threat Actor Type: Ransomware-as-a-Service (RaaS) with a multi-track affiliate program, data-theft extortion, optional destructive wiping, and an active public media strategy. 

Structure: Core operators manage the malware, backend negotiation infrastructure, leak site, and affiliate panel. Affiliates conduct intrusions independently and are responsible for initial access, lateral movement, and payload execution. Operators are active on the RAMP and XSS Russian-language underground forums under the personas “superSonic” and “Anubis__media.” The group also maintains a public X/Twitter account and has positioned itself as a media contact — actively reaching out to journalists and offering exclusive access to stolen datasets as a supplemental pressure tactic. 

Affiliate Program — Three Distinct Tracks: Anubis advertises an unusually flexible and multi-layered affiliate model, formally announced on the RAMP forum on February 23, 2025: 

    1. Traditional RaaS: Affiliates conduct intrusions and deploy Anubis ransomware. Operators take 20%; affiliates retain 80% of ransom proceeds. 
    2. Data Extortion Program: Affiliates supply stolen datasets to Anubis operators, who handle extortion on their behalf. Revenue split: 60% to the affiliate. Data must be no older than six months, previously unpublished, and sensitive enough to leverage. This track lowers the barrier to entry for criminals who have stolen data but lack ransomware capabilities. 
    3. Access Monetization Program: Affiliates sell corporate network access to Anubis operators, who then conduct or broker the intrusion. Revenue split: 50% to the affiliate. Designed to attract initial access brokers (IABs) into the Anubis ecosystem. 

Operators: Forum posts and communications are written in Russian, supporting an assessment of a Russian-speaking operator or affiliate base. Some researchers assess that observed activity is consistent with CIS-aligned operating patterns, but no individual identities or definitive geographic attribution have been publicly established. 

Expertise: Anubis is technically distinguished by a dual-impact model: standard file encryption combined with an optional destructive mode activated with the /WIPEMODE parameter. When activated, the wiper erases file contents and can reduce affected files to 0 KB while leaving filenames and directory structures intact. This makes recovery from those files impossible even if a decryption key is later available. Combined with data theft, the capability adds destructive pressure to a conventional double-extortion operation. 

  • Cross-platform coverage is comprehensive: Anubis supports Windows, Linux, NAS devices, and VMware ESXi hypervisors. The encryptor includes built-in domain-wide self-propagation and supports multiple configurable encryption modes. Files are renamed with the .anubis extension; ransom notes are dropped as RESTORE FILES.html in all affected directories. 

 

Motivations 

Financial gain through ransomware deployment, data extortion, and access monetization is the primary documented motive. Public reporting has not identified ideological or state-directed objectives. Claims about geographic targeting restrictions should be treated as operator policy statements rather than proof of the group’s location or sponsorship. 

 

Timeline & Victimology 

Figure 1: Victim heatmap.

November–December 2024 — Emergence as Sphinx 

Early ransomware samples circulate under the codename “Sphinx.” Ransom notes lack Tor site links and unique victim identifiers — indicators of a group still in active development. A healthcare organization in Canada is among the first confirmed victims. 

December 29, 2024 — First Publicly Named Victim 

Pound Road Medical Centre in Australia becomes the first victim publicly claimed on the Anubis leak site, establishing the group’s healthcare targeting pattern from day one. 

February 2025 — Formal Launch and Affiliate Recruitment 

Anubis formally rebrands from Sphinx and launches its affiliate program. “superSonic” posts the three-track affiliate program to the RAMP forum on February 23, 2025. “Anubis__media” establishes presence on XSS. The leak site goes live with an onion-hosted blog and a public FAQ detailing extortion policies. 

Early–Mid 2025 — Sector Diversification 

Anubis expands victim claims across healthcare, engineering, construction, hospitality, and technology. Victims are recorded across Australia, Canada, Peru, and the United States.  

January–March 2026 — Activity Surge 

Ransom-DB documents a dramatic escalation in Anubis activity: tracked data points rise from 187 to over 2,600 between late 2025 and March 2026, with multiple attacks recorded per week including on consecutive days. Intrusions linked to exploitation of CitrixBleed 2 (CVE-2025-5777) are tied to Anubis-linked affiliate tradecraft in incident reporting during this period. 

As of July 30, 2026 — 99 Publicly Claimed Victims 

Ransomware.live records 99 victims publicly claimed by Anubis as of July 30, 2026. The tracker lists the most recent claim on July 28, 2026. Leak-site totals represent publicly posted claims, not independently confirmed infections or the full number of affected organizations. 

July 16–27, 2026 — Fairlife / Coca-Cola 

The Coca-Cola Company disclosed in a July 16 Form 8-K that unauthorized access to part of Fairlife’s systems, including production-related systems, temporarily disrupted U.S. production; Canadian operations and product quality and safety were not affected. Anubis later claimed responsibility and alleged that it encrypted Fairlife’s Nutanix infrastructure and stole approximately 1 TB of corporate data.

 

See how one manufacturer strengthened ransomware resilience across its virtualized environment—and the practical steps it took to reduce risk before an attack disrupted operations

 

Read the full case study

 

Tactics & Techniques 

Initial Access 

  • T1190 – Exploit Public-Facing Application (confirmed: CVE-2025-5777 CitrixBleed 2) 
  • T1566 – Phishing / Spear-Phishing 
  • T1078 – Valid Accounts (stolen VPN credentials via IABs) 

Execution 

  • T1059 – Command and Scripting Interpreter (configurable flags: /WIPEMODE/NOENCRYPT, propagation) 
  • T1489 – Service Stop (security tools, backup agents, database services terminated pre-encryption) 

Persistence & Privilege Escalation 

  • T1078 – Valid Accounts (valid VPN credentials observed in documented intrusions) 
  • T1219 – Remote Access Software (abuse of legitimate RMM and remote administration tools, including ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, and Total Software Deployment) 

Defense Evasion 

  • T1562.001 – Impair Defenses: Disable or Modify Tools 
  • T1490 – Inhibit System Recovery (Volume Shadow Copy deletion) 

Discovery 

  • T1018 – Remote System Discovery 
  • T1046 – Network Service Discovery 
  • T1135 – Network Share Discovery 

Exfiltration 

  • Data theft has been reported in Anubis incidents, but public reporting does not consistently establish a specific exfiltration channel.

Command & Control 

  • T1219 – Remote Access Software (legitimate RMM and remote administration tools used to maintain control) 
  • T1090 – Proxy (authenticated proxies and SSH-based SOCKS tunneling observed in documented intrusions) 

Impact 

  • T1486 – Data Encrypted for Impact (ECIES encryption; .anubis extension; RESTORE FILES.html ransom note) 
  • T1485 – Data Destruction (/WIPEMODE: permanent irreversible file overwrite — recovery impossible even with decryption key) 
  • T1490 – Inhibit System Recovery (shadow copy and backup deletion) 
  • T1657 – Financial Theft (financially motivated ransomware, data-extortion, and access-monetization activity) 

 

Defensive Recommendations Against Anubis 

Patch CVE-2025-5777 and harden remote access. Verify patch status on all internet-facing Citrix NetScaler appliances immediately. Enforce MFA on all VPN and remote access endpoints and rotate credentials — Anubis affiliates also purchase stolen VPN credentials from IABs. 

Detect pre-encryption activity, not just ransomware signatures. Anubis exfiltrates before encrypting and its wipe mode makes post-encryption recovery irrelevant. Alert on early signals in combination: mass service termination, shadow copy deletion, large outbound transfers, and domain enumeration from non-admin hosts. 

Use behavioral detection across affected platforms. Monitor for destructive file operations and the sequence of behaviors that can precede encryption, including unusual RMM deployment, credential access, service termination, shadow copy deletion, and movement toward hypervisors, NAS, and backup-adjacent systems. Behavioral controls can complement signatures by detecting activity before or during mass file modification. 

Harden hyperconverged and virtualization management planes. Anubis has publicly claimed encryption of Fairlife’s Nutanix infrastructure, but that specific claim has not been independently confirmed by Coca-Cola. Regardless, documented Anubis intrusions have targeted hypervisors, NAS devices, domain controllers, and backup-adjacent systems. Enforce MFA, restrict management interfaces, segment clusters from user networks, monitor privileged activity, and maintain isolated recovery copies. 

Maintain offline, air-gapped backups and test them. If wipe mode deploys, backups are the only recovery path — and only if unreachable from the compromised environment. 

 

References 

Arctic Wolf Labs. From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks. https://arcticwolf.com/resources/blog/citrixbleed-2-to-cloudflared-the-tools-and-techniques-behind-anubis-ransomware-attacks/  

Trend Micro. Anubis: A Closer Look at an Emerging Ransomware with Built-in Wiper. https://www.trendmicro.com/en_gb/research/25/f/anubis-a-closer-look-at-an-emerging-ransomware.html  

KELA Cyber. Anubis: A New Ransomware Threat. https://www.kelacyber.com/blog/anubis-a-new-ransomware-threat/  

Ransomware.live. Anubis Group Profile. https://www.ransomware.live/group/Anubis 

U.S. Securities and Exchange Commission. The Coca-Cola Company Form 8-K, July 16, 2026. https://www.sec.gov/Archives/edgar/data/21344/000162828026048466/ko-20260716.htm  

BleepingComputer. Anubis Ransomware Claims Coca-Cola Fairlife Attack, Threatens Data Leak. https://www.bleepingcomputer.com/news/security/anubis-ransomware-claims-coca-cola-fairlife-attack-threatens-data-leak/  

Mallory AI. Anubis Ransomware Expanded Through Forum Branding and CitrixBleed 2 Intrusions. https://www.mallory.ai/stories/019f1d2a-4f07-7c99-9993-d7767fa6cb01  

Picus Security. Anubis Ransomware Targets Global Victims with Wiper Functionality. https://www.picussecurity.com/resource/blog/anubis-ransomware-targets-global-victims-with-wiper-functionality  

Proven Data. Anubis Ransomware: Operational Profile, Attack Chain, and Response Priorities. https://www.provendata.com/blog/anubis-ransomware  

Ransom-DB. Anubis Ransomware Group Analysis 2026. https://www.ransom-db.com/blog/anubis-ransomware-group-analysis-2026  

SecurityWeek. Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife. https://www.securityweek.com/ransomware-group-threatening-to-leak-data-stolen-from-coca-colas-fairlife/  

The Hacker News. Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials. https://thehackernews.com/2026/07/ransomware-groups-turn-to-citrix-bleed.html