Anubis Ransomware Deploys Devastating Wiper Module That Makes File Recovery Impossible Even After Ransom Payment


# Anubis Ransomware Adds Destructive Wiper Feature to Increase Victim Pressure

The Anubis ransomware-as-a-service (RaaS) operation has introduced a dangerous new capability: a file-wiping module that permanently destroys data, making recovery impossible even after ransom payment.

## Emerging Threat with Growing Ambitions

Anubis, a relatively new ransomware family first detected in December 2024, has rapidly evolved since becoming active earlier this year. The operators launched an affiliate program on the RAMP forum in February, offering attractive profit-sharing arrangements: 80% for ransomware affiliates, 60% for data extortion partners, and 50% for initial access brokers.

Currently, only eight victims appear on Anubis’ dark web extortion site, suggesting the operation is still building momentum while refining its technical capabilities.

## Revolutionary Wiper Functionality

According to a recent Trend Micro report, Anubis now incorporates a file-wiping feature that sets it apart from other ransomware operations. This destructive capability is designed to pressure victims into paying quickly rather than attempting to negotiate or ignore ransom demands.

The wiper function activates through a command-line parameter ‘/WIPEMODE’ that requires key-based authentication. When enabled, it completely erases file contents while preserving filenames and directory structures. Victims see their files in expected locations, but the data is irreversibly destroyed—reduced to 0 KB with no possibility of recovery.

## Technical Specifications

Anubis employs sophisticated encryption using ECIES (Elliptic Curve Integrated Encryption Scheme) and shares implementation similarities with EvilByte and Prince ransomware families. The malware:

– Supports multiple launch commands for privilege elevation and directory targeting
– Excludes critical system directories to maintain system functionality
– Removes Volume Shadow Copies to prevent recovery
– Terminates interfering processes and services
– Appends ‘.anubis’ extensions to encrypted files
– Drops HTML ransom notes in affected directories

## Attack Methods and Prevention

Anubis infections typically begin through phishing emails containing malicious links or attachments. Organizations should implement robust email security measures and maintain updated threat intelligence to defend against this evolving ransomware threat.

The addition of permanent data destruction capabilities represents a concerning escalation in ransomware tactics, emphasizing the critical importance of comprehensive backup strategies and proactive cybersecurity measures.

Share This Article