Anubis Ransomware

Description Summary

Added a WIPER (/WIPEMODE) that zeroes files (0 KB) — recovery impossible even if the ransom is paid.

Threat Actor

RaaS (80% affiliate); integrated wiper module; spear-phishing initial access.

Technical Indicators

Encryption Extension
.anubis
Encryption Algorithm
ECIES (Elliptic Curve Integrated Encryption Scheme)
Ransom Note Name
Not publicly reported
Targeted Industries
Healthcare, Construction, Engineering
First Seen
December 2024 (RaaS February 2025)
Last Seen
Active
Geographical Location
Australia, Canada, Peru, US

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Impact x 2 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
Exfiltration x 1 T1567 Exfiltration Over Web Service (leak site)
Initial Access x 2 T1190 Exploit Public-Facing Application
T1078 Valid Accounts