
A dangerous new ransomware strain called Anubis has emerged with an unprecedented dual-threat capability that both encrypts and permanently destroys files, making data recovery impossible even after ransom payment.
## Key Features and Operations
Trend Micro researchers identified this ransomware-as-a-service (RaaS) operation, which became active in December 2024. Unlike traditional ransomware that only encrypts files, Anubis features a destructive “wipe mode” that permanently erases file contents while leaving filenames intact, reducing file sizes to 0 KB.
The malware, initially developed under the name “Sphinx,” operates through a flexible affiliate program with attractive revenue splits:
– Standard ransomware operations: 80-20 split (affiliates receive 80%)
– Data extortion schemes: 60-40 split
– Access sales: 50-50 split
## Attack Methods and Targets
Anubis primarily spreads through phishing emails and has successfully targeted organizations across multiple sectors including healthcare, hospitality, and construction in Australia, Canada, Peru, and the United States.
The attack sequence follows a systematic approach:
1. Initial access via phishing emails
2. Privilege escalation and network reconnaissance
3. Deletion of volume shadow copies
4. File encryption and optional content wiping
## Increased Pressure Tactics
The ransomware’s ability to permanently destroy data significantly escalates pressure on victims to pay ransoms quickly. The wipe function, activated through a “/WIPEMODE parameter,” ensures that traditional recovery methods become completely ineffective.
## Related Threats
This discovery coincides with new intelligence about the FIN7 cybercriminal group, which has been using fake software distribution sites to deliver NetSupport RAT malware. The group employs three main distribution methods: bogus browser updates, fake 7-Zip download sites, and TAG-124 traffic distribution systems.
## Security Implications
The emergence of Anubis represents a concerning evolution in ransomware tactics, where cybercriminals are moving beyond encryption to complete data destruction, fundamentally changing the risk landscape for potential victims and emphasizing the critical importance of robust backup and prevention strategies.
