Anubis Ransomware: What Businesses Need to Know About This Emerging Threat
Ransomware continues to evolve, with cybercriminal groups constantly developing new ways to compromise organizations, steal sensitive information, and increase pressure on victims. One emerging threat drawing attention is Anubis ransomware, a Ransomware-as-a-Service (RaaS) operation that has introduced a particularly destructive capability: the option to permanently wipe files.
Understanding how Anubis operates, who it targets, and how attackers gain access can help organizations strengthen their defenses against this growing ransomware threat.
What Is Anubis Ransomware?
Anubis is a ransomware operation that first appeared under the name Sphinx before rebranding in late 2024. While the earlier Sphinx operation used the “.sphinx” extension for encrypted files, the newer Anubis ransomware uses the “.anubis” extension.
The operation follows a Ransomware-as-a-Service (RaaS) model. This means the ransomware infrastructure and tools can be used by affiliates to carry out attacks, allowing cybercriminals with varying levels of technical expertise to participate in ransomware operations.
Anubis has reportedly attracted affiliates by offering them a significant share of ransom payments, making the operation appealing to cybercriminals around the world.
What Makes Anubis Different?
Many modern ransomware groups use a double-extortion strategy. They first steal sensitive data and then encrypt the victim’s files. The attackers threaten to publish the stolen information unless the ransom is paid.
Anubis can take this threat a step further.
The ransomware includes an optional “wipe mode” that can permanently erase the contents of files instead of simply encrypting them. After the wiping process, affected files can appear as zero-byte files, meaning their original contents may no longer be recoverable.
This capability creates additional pressure on victims. Organizations that rely only on the assumption that encrypted files can eventually be restored may face a much more serious situation if their data has been permanently destroyed.
This is why maintaining reliable, offline, and regularly tested backups remains a critical part of ransomware preparedness.
Who Is Being Targeted?
Healthcare organizations appear to be among the sectors particularly affected by Anubis attacks. One reported incident involved the Mississippi-based Singing River Health System, where attackers reportedly compromised the organization’s network and stole sensitive information.
However, healthcare is not the only sector at risk. Anubis has also been associated with attacks targeting organizations in industries such as:
- Manufacturing
- Construction
- Legal services
- Financial services
The range of targeted industries highlights an important point: ransomware threats such as Anubis can affect organizations of different sizes and across multiple sectors.
How Does Anubis Gain Access?
According to researchers cited by Fortra, Anubis attackers have used multiple methods to gain initial access to victim environments.
One identified method is spear phishing. Attackers can send carefully crafted emails containing malicious attachments or links designed to trick targeted individuals into interacting with them.
Another recently identified attack path involves exploiting CitrixBleed 2 (CVE-2025-5777), a vulnerability affecting Citrix NetScaler appliances. Exploiting this vulnerability can expose session tokens and potentially allow attackers to bypass multi-factor authentication.
Once attackers gain access, they may move laterally through the organization’s network using legitimate remote management tools. Using trusted tools can help attackers blend into normal activity and make detection more difficult.
Why Anubis Is a Serious Threat
Anubis highlights how modern ransomware attacks are becoming increasingly focused on maximizing pressure on victims.
The threat is not limited to encrypting files. Attackers may combine:
- Initial access through phishing or exploited vulnerabilities
- Theft of sensitive organizational data
- Lateral movement across the network
- Data extortion and leak threats
- File encryption
- Permanent data wiping
This combination can create significant operational, financial, and reputational consequences for affected organizations.
For businesses, the lesson is clear: ransomware defense cannot depend on a single security control. Organizations need a layered approach that addresses email threats, vulnerabilities, identity security, endpoint activity, network access, and data protection.
How Organizations Can Protect Against Anubis
Organizations can take several important steps to reduce their risk.
1. Keep Systems and Software Patched
Organizations should prioritize critical security updates and ensure internet-facing systems are regularly patched. For environments using affected Citrix NetScaler appliances, organizations should address CVE-2025-5777 immediately and follow the vendor’s recommended steps after patching.
2. Strengthen Multi-Factor Authentication
MFA adds an additional layer of protection against stolen credentials. Organizations should enforce MFA, particularly for remote access and other critical systems.
However, organizations should also recognize that MFA alone is not a complete defense. Attackers may attempt to bypass authentication through vulnerabilities or other techniques, making a layered security strategy essential.
3. Monitor Remote Management Tools
Remote management tools can be useful for legitimate IT operations, but attackers may also abuse them after gaining access to an environment.
Organizations should maintain an inventory of approved remote management tools and monitor for unexpected or unauthorized tools being deployed.
4. Maintain Offline and Tested Backups
Backups remain one of the most important defenses against ransomware. However, backups should not simply exist. Organizations should regularly test whether their backups can actually be restored.
Keeping copies offline or otherwise protected from unauthorized access can help reduce the risk of attackers compromising backup systems during an attack.
5. Strengthen Phishing Awareness
Because spear-phishing can be used as an entry point, employees should be trained to recognize suspicious emails, unexpected attachments, and unusual links.
Security awareness training and phishing simulations can help employees identify potential threats before they become an entry point into the organization’s network.
Anubis ransomware demonstrates how modern cyber threats continue to evolve beyond traditional file encryption. With capabilities that can include data theft, extortion, encryption, and permanent file wiping, the consequences of a successful attack can be severe.
Organizations should not wait until an attack occurs to prepare. By keeping systems patched, strengthening MFA, monitoring remote access and management tools, training employees, and maintaining reliable offline backups, businesses can improve their resilience against ransomware threats such as Anubis.
The most important takeaway is simple: Ransomware protection is not just about preventing encryption. It is about protecting access, identities, systems, and the data that keeps your business running.
