Anubis — Ransomware Profile

Anubis is a ransomware-as-a-service (RaaS) operation that emerged in December 2024 as a rebrand of the earlier Sphinx encryptor, signaled by a file-extension change from .sphinx to .anubis. Operators announced a "new format" affiliate program on the RAMP forum on 23 February 2025 (personas "superSonic" on RAMP, "Anubis__media" on XSS), with negotiable revenue splits across three tracks: standard ransomware (about 80/20 to the affiliate), data extortion (about 60/40), and access monetization (about 50/50). The Go-based encryptor uses ECIES public-key encryption, deletes volume shadow copies, and adds a destructive /WIPEMODE that zeroes file contents to block recovery even after payment; Windows and Linux variants exist. Beyond spear-phishing, 2026 intrusions investigated by Arctic Wolf used valid VPN credentials and CitrixBleed 2 (CVE-2025-5777) for initial access, followed by RMM abuse (ScreenConnect, Zoho Assist, MeshAgent) and Mimikatz. Victims span healthcare, engineering, construction, and professional services across Australia, Canada, Peru, and the US.

Also tracked as

Sphinx (predecessor)

Tools & malware

Recent claimed victims

Vendor research

Read the full analysis on IntelFusions