# Anubis Ransomware: The New Egyptian Plague Targeting Critical Infrastructure


A newly rebranded ransomware-as-a-service (RaaS) operation is raising the stakes in extortion campaigns by combining traditional encryption with an irreversible data-destruction capability—creating unprecedented pressure on victims to pay. Anubis, which emerged in late 2024 as a rebrand of the Sphinx ransomware group, has already claimed approximately 90 victims globally and has shown a particular appetite for healthcare providers, manufacturing firms, and other critical sectors.


What sets Anubis apart from competitors in an already brutal threat landscape is a built-in "wipe mode" feature that permanently obliterates file contents rather than simply encrypting them—a technical escalation that transforms ransomware from a recoverable extortion threat into potential permanent data loss.


## What Is Anubis Ransomware?


Anubis is a ransomware-as-a-service operation that offers a franchise model for cybercriminals worldwide. The group provides the underlying ransomware code, infrastructure, and leak site management, while affiliate operators conduct the actual intrusions and negotiations with victims. This model is neither new nor unique in the ransomware ecosystem—but Anubis's aggressive expansion and operational maturity suggest it is quickly becoming a serious player.


The group's name borrows from ancient Egyptian mythology (Anubis being the god of the dead and mummification), a branding convention common among modern ransomware gangs who often adopt elaborate mythological or thematic names. File extensions encrypted by Anubis are appended with ".anubis"—a calling card left on every compromised system.


## From Sphinx to Anubis: The Rebranding


Anubis did not emerge from nowhere. Researchers tracking the group's evolution have identified its predecessor: Sphinx ransomware, which operated under a similar RaaS model and appended ".sphinx" extensions to encrypted files. The rebranding in late 2024 represented either a strategic pivot or a necessary operational security measure—rebrands are common in the ransomware space when groups face increased law enforcement pressure or when they seek to rebrand their "product" for marketing reasons.


What remained consistent across the transition was the core business model: offering affiliates up to 80% of ransom proceeds. This extraordinarily generous cut makes Anubis exceptionally attractive to financially motivated threat actors across the globe, effectively lowering the barrier to entry for organized cybercriminals and opportunistic threat groups alike.


Regional Attribution & Membership


Although no definitive regional attribution has been confirmed by Western intelligence agencies, researchers have observed that Anubis operators make announcements and community posts predominantly in Russian—a pattern common among Eastern European and Russian-speaking cybercriminal forums. However, the high affiliate payout suggests the group actively recruits internationally, meaning individual operators may originate from anywhere, from Brazil to Vietnam to Eastern Europe.


## The Wipe Mode: An Escalation in Ransomware Tactics


The most distinctive and troubling feature of Anubis is its optional "wipe mode"—a built-in capability that goes beyond the standard ransomware playbook. Rather than simply encrypting files (which can theoretically be recovered or decrypted), wipe mode permanently erases file contents, rendering them unrecoverable by any forensic or recovery method.


After files pass through wipe mode processing, they register as zero bytes in the file system—completely irretrievable. This irreversible destruction applies asymmetric psychological pressure on victims:


  • Traditional ransomware: Pay or restore from backups
  • Anubis with wipe mode: Pay or lose data permanently (backup or not, if wipe mode was used)

  • This escalation transforms ransomware from an extortion threat into a data destruction threat. For organizations with compliance obligations around data retention—healthcare providers, financial firms, law firms—the permanent loss of records creates cascading legal and regulatory consequences beyond the ransom itself.


    ## Targeting Patterns: Healthcare in the Crosshairs


    As of early July 2026, Anubis has claimed approximately 90 victims on its dark web leak site. The healthcare sector has been disproportionately targeted, a pattern that warrants urgent attention.


    A particularly severe case involved Singing River Health System, a Mississippi-based hospital network serving over 100,000 patients annually. In the Anubis compromise:


  • 293GB of data were exfiltrated
  • Over 1.2 million files were stolen
  • Stolen data included:
  • - Contact information and Social Security numbers

    - Dates of birth and patient IDs

    - Treatment histories and diagnostic test results

    - Medication lists and health insurance numbers

    - Intimate surgical images and provider credentials

    - Bank account information


    Critically, this was Singing River's second major ransomware incident in two years—it had previously fallen victim to the Rhysida ransomware gang in 2023. The repeat targeting suggests either inadequate remediation after the first attack or that healthcare networks remain structurally vulnerable to ransomware regardless of defensive investments.


    | Sector | Victim Count | Geographic Distribution |

    |--------|--------------|------------------------|

    | Healthcare | 15+ (estimated) | US, UK, Australia |

    | Manufacturing | ~25 | US, EU, Asia-Pacific |

    | Legal Services | ~12 | US, UK |

    | Financial Services | ~10 | Global |

    | Construction | ~8 | US, Canada |

    | Other sectors | ~20 | Multiple regions |


    Geographic concentration is heavily skewed toward English-speaking nations with higher ransom-paying capacity: the United States accounts for the largest victim share, followed by the UK, Australia, France, and Canada.


    ## Attack Vectors: Spear-Phishing and Unpatched Vulnerabilities


    Anubis employs both traditional and opportunistic attack methods:


    ### Spear-Phishing with Malicious Attachments

    The group crafts convincing phishing emails targeting specific organizations, often using stolen corporate context or mimicked communication styles. Attachments or embedded links deliver initial access malware.


    ### CVE-2025-5777 (CitrixBleed 2) Exploitation

    More concerning is the group's recent exploitation of CitrixBleed 2, a critical vulnerability affecting Citrix NetScaler appliances. This vulnerability:


  • Requires no user interaction to exploit
  • Exposes session tokens and authentication credentials
  • Bypasses multi-factor authentication (MFA)—a devastating capability that neutralizes what many organizations consider their primary defense

  • Every unpatched NetScaler appliance represents an open door into the network, particularly for organizations that use Citrix for remote access. The exploitation pattern suggests attackers are actively scanning for vulnerable instances and moving laterally into networks within hours of initial compromise.


    ### Lateral Movement

    Once inside, Anubis operators deploy legitimate remote management tools (RDP, RMM software, Citrix, VPN clients) to spread laterally without triggering security alerts. This "living off the land" technique mimics normal administrative activity, making detection significantly harder for monitoring systems tuned to flag obviously malicious behavior.


    ## Real-World Impact and Business Continuity Risks


    The Anubis attacks against healthcare have demonstrated the tangible impact of modern ransomware:


  • Patient care disruptions: Hospitals must divert emergency cases or operate with paper-based systems
  • Regulatory penalties: Healthcare organizations violate HIPAA and state breach notification laws upon data disclosure
  • Ransom demands: Reported ransom figures for Anubis attacks typically range from $500,000 to several million dollars
  • Reputational damage: Public disclosure of intimate surgical images and patient data erodes patient trust

  • Manufacturing and financial targets face equally severe consequences: supply chain disruptions, regulatory compliance violations, and reputational harm.


    ## Defense and Mitigation Strategies


    Organizations must adopt a layered defense strategy that combines preventative measures with recovery readiness:


    ### Immediate Priorities

    1. Patch CVE-2025-5777 on all Citrix NetScaler appliances immediately

    - This is not optional; every day a vulnerability remains unpatched is a day an attacker could gain network access

    - After patching, terminate all active sessions per Citrix's remediation guidance

    - Consider forcing password resets for all accounts that accessed Citrix during the vulnerability window


    2. Enforce multi-factor authentication (MFA) on all remote access points

    - VPN

    - Citrix and terminal services

    - Cloud management portals

    - Email systems

    - This prevents compromised credentials from enabling unauthorized access


    3. Implement and test ransomware backups

    - Air-gap critical backups from network connectivity

    - Test restoration procedures quarterly (not just once)

    - Ensure backups cannot be deleted or encrypted by an attacker with domain admin credentials


    ### Ongoing Controls

  • Deploy behavioral detection systems that flag unusual lateral movement and file system activity
  • Conduct spear-phishing simulation campaigns and track employee vulnerability
  • Maintain current asset inventory and vulnerability scanning
  • Implement application whitelisting on critical systems
  • Enforce principle of least privilege for network access
  • Conduct threat hunts specifically looking for Anubis TTPs (techniques, tactics, procedures)

  • ---


    ## HackWire Analysis


    Anubis represents a critical inflection point in ransomware evolution. The addition of permanent data wipe functionality crosses a psychological and operational threshold that transforms the threat model: backups, once a reliable last-resort defense, no longer guarantee recovery if an attacker chooses to destroy rather than encrypt.


    More broadly, Anubis exemplifies how modern ransomware has become industrialized and democratized. By offering 80% payouts to affiliates, the group has essentially franchised cybercrime to thousands of operators worldwide—lowering the technical skill floor and expanding the threat surface to every organization, regardless of size. The fact that healthcare has been repeatedly targeted (Singing River's second compromise in two years) signals that the sector remains systematically vulnerable despite well-publicized ransomware incidents.


    The exploitation of CitrixBleed 2 reveals another uncomfortable truth: a single unpatched vulnerability on an otherwise hardened network becomes a critical liability in an era of sophisticated attackers. The capability to bypass MFA—traditionally the security industry's go-to recommendation—exposes the limits of layered defense when any single layer has a catastrophic flaw.


    For defenders, the implication is clear: this is not a year to iterate or plan incrementally. Organizations must treat unpatched critical vulnerabilities on internet-facing assets as active emergencies, not items for the next patch cycle. They must rebuild backup strategies around the assumption that data destruction, not just theft, is a viable attacker strategy. And they must recognize that "good enough" security no longer protects against operations as well-resourced and persistent as Anubis.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)