Anubis is a financially motivated cybercrime group primarily known for its banking trojan operations but also linked to ransomware activity targeting corporate networks. First identified in 2016 and evolving over time, Anubis ransomware attacks have targeted Windows systems, often deployed after initial compromises by the Anubis banking malware or other access vectors such as phishing, malicious email attachments, or exploitation of unpatched vulnerabilities. The group’s ransomware encrypts files using strong symmetric encryption algorithms, appending distinctive extensions and delivering ransom notes with payment instructions via Tor. Anubis has targeted multiple sectors worldwide, including finance, retail, and government, often combining ransomware with credential theft and data exfiltration to maximize pressure on victims. Its infrastructure and tactics overlap with other financially motivated actors, suggesting possible affiliate or shared tool usage within broader cybercriminal ecosystems.
Genera un perfil del actor con IA (defensivo) cuando lo pidas.
Este grupo no tiene TTPs curadas. Puedes generar un mapeo MITRE ESTIMADO por IA (no confirmado) a partir de su descripción/notas, solo cuando lo pidas.
Firma de detección defensiva para este grupo (úsala en tu EDR/SIEM). Fuente: ransomware.live.
/*
anubis ransomware
*/
rule anubis_Ransomnote
{
meta:
author = "ransomware.live"
family = "ransomware.anubis"
description = "Detects anubis ransomware ransom note or artifact"
date = "2026-05-04"
severity = 7
score = 70
strings:
$name1 = "anubis" ascii nocase
$name2 = "ANUBIS" ascii
$onion = "anubis.onion" ascii nocase
condition:
any of them
}
Good afternoon, [snip]! This is the ANUBIS hacker team. We want to let you know that we have been on your network for a long time and have been studying your company's business. We have downloaded gigabytes of your data, which is now being analyzed by our best experts. Contact us and we will provide you with a list of files that we have. If we can't reach an agreement, we will notify every customer of the data leak. If you ignore or refuse the deal, we will be forced to publish all your data in the public domain. As our blog grows and attracts media attention every day, the case will become publicized and cause devastating damage to your business. The only way to avoid this is to make a deal with us. Appoint a responsible person to negotiate and get down to business. Otherwise, every client will see how you disregarded their personal information and will have a detailed plan on how to win a case against you in court. To contact us and resolve this issue, you need to access us via TorBrowser ([redactado] We regularly send you a chat link and your credentials through your website. You will need to act strictly according to the instructions. In addition, we have sent you confirmation that we hold all your data. Then go to our website: [redactado] And enter your unique ID: [snip] I also recommend visiting our blog via the Tor browser, there, we post files from companies that refuse to pay. The same fate awaits you if we dont reach an agreement. Our blog is followed by the global media. [redactado]
Data breach at a major healthcare franchise headquarters.
Data breach at a global leader in packaging manufacturing.
| Organización | País | Sector | Grupo | Descubierta |
|---|---|---|---|---|
| Interim HealthCare [Head office] | US | Healthcare | — | 21 ago 2026 |
| Scholle IPN / SIG | DE | Manufacturing | — | 18 ago 2026 |
| Interim HealthCare | US | Healthcare | — | 15 ago 2026 |
| Cleaver-Brooks | US | Manufacturing | — | 10 ago 2026 |
| BLACKBURN'S | US | Healthcare | — | 3 ago 2026 |
| Cameron Regional Medical Center | US | Healthcare | — | 3 ago 2026 |
| Winn-Dixie | US | Retail & E-Commerce | — | 3 ago 2026 |
| Prelys Courtage | FR | Financial Services | — | 28 jul 2026 |
| Coca-Cola / Fairlife | US | Agriculture and Food Production | — | 27 jul 2026 |
| Eagle Crest Communities | US | Hospitality | — | 26 jul 2026 |
| Bath Fitter | US | Consumer Services | — | 20 jul 2026 |
| Fairlife / Coca-Cola | US | Agriculture and Food Production | — | 20 jul 2026 |
| Casper Orthopedics | US | Healthcare | — | 12 jul 2026 |
| Surtifamiliar | CO | Not Found | — | 12 jul 2026 |
| Community Advocates | Business Services | — | 12 jul 2026 | |
| Ferrum AG | CH | Manufacturing | — | 3 jul 2026 |
| Quest Healthcare Solutions | US | Healthcare | — | 2 jul 2026 |
| Northeast Pediatrics & Adolescent Medicine | Healthcare | — | 2 jul 2026 | |
| ESMS Global Limited | GB | Business Services | — | 29 jun 2026 |
| Boston Orthotics & Prosthetics | US | Healthcare | — | 29 jun 2026 |
| Nachlass Nord | DE | Business Services | — | 25 jun 2026 |
| Quest Health Solutions | US | Healthcare | — | 24 jun 2026 |
| KTR Real Estate Advisors | US | Financial Services | — | 19 jun 2026 |
| KoMiCo | Not Found | — | 15 jun 2026 | |
| FÉTIS Group & SECOM Engineering | FR | Business Services | — | 11 jun 2026 |
| Jeffrey Burr | US | Consumer Services | — | 5 jun 2026 |
| D&M Contractors | GB | Construction | — | 5 jun 2026 |
| Singing River Health System | US | Healthcare | — | 3 jun 2026 |
| Power & Tel | Telecommunication | — | 1 jun 2026 | |
| EXCEED Energy | Energy | — | 27 may 2026 | |
| Copec S.A. | CL | Energy & Utilities | — | 14 ene 2026 |
| Comercializadora S&E Perú | PE | Energy & Utilities | — | 25 feb 2025 |
Las direcciones de los sitios de filtración (.onion) se conocen pero no se publican ni se enlazan. Solo se muestran metadatos públicos. ética
Home Healthcare Agency & Medical Staffing.
Major data breach at a leading industrial manufacturer.
Major home healthcare provider data breach.
Patient and employee data breach at a healthcare provider.