Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Anubis Ransomware Packs a Wiper to Permanently Delete Files

Posted on June 16, 2025June 16, 2025 By CWS

The rising Anubis ransomware has turn out to be a serious risk to organizations, as it could actually completely delete recordsdata to forestall their restoration, Pattern Micro warns.

Energetic since late 2024 and working below the ransomware-as-a-service (RaaS) mannequin, Anubis was first detailed in February this yr, when risk intelligence agency Kela noticed it primarily specializing in knowledge extortion, with out the encryption element.

A recent Pattern Micro report, nevertheless, places issues in a unique perspective: not solely does Anubis encrypt victims’ knowledge, nevertheless it additionally has a wiper module that destroys it.

“Pattern Analysis has noticed particular command line operations for these damaging actions, together with makes an attempt to vary system settings and wipe directories,” the cybersecurity agency notes.

In keeping with Pattern Micro, Anubis, which has the identical code as Sphinx, apart from the operate that generates the ransom observe, has been promoted on cybercrime boards by two accounts, particularly ‘supersonic’ and ‘Anubis__media’.

Associates are promised negotiable revenue-share constructions for long-term cooperation, in addition to entry to applications past the everyday RaaS and double extortion for monetization, particularly a knowledge ransomware affiliate and an entry monetization associates program.

So far, the group has focused development, engineering, and healthcare organizations in Australia, Canada, Peru, and the USA, with seven victims listed on Anubis’ Tor-based leak web site.

Anubis’ operators depend on spear phishing emails for preliminary entry. As soon as in, they depend on numerous instructions and scripts to verify for administrative privileges, try and elevate them to System, after which proceed to file and listing discovery.Commercial. Scroll to proceed studying.

The ransomware additionally targets particular processes for termination, erases Quantity Shadow copies, and encrypts sufferer’s knowledge utilizing Elliptic Curve Built-in Encryption Scheme (ECIES) encryption. It then drops an icon file to the Program Knowledge folder, and makes an attempt to vary the desktop wallpaper to its personal.

Within the dropped ransom observe, the RaaS operators threaten to launch the sufferer’s stolen knowledge until a ransom is paid.

The wiper module in Anubis, Pattern Micro explains, can be utilized to completely delete the contents of a file, making restoration unattainable.

“What additional units Anubis other than different RaaS and lends an edge to its operations is its use of a file wiping function, designed to sabotage restoration efforts even after encryption. This damaging tendency provides stress on victims and raises the stakes of an already damaging assault,” Pattern Micro notes.

Associated: Fog Ransomware Assault Employs Uncommon Instruments

Associated: Are Risk Teams Belsen and ZeroSevenGroup Associated?

Associated: On Demand: Risk Detection & Incident Response (TDIR) Summit

Associated: Sharing Intelligence Past CTI Groups, Throughout Wider Features and Departments

Security Week News Tags:Anubis, Delete, Files, Packs, Permanently, Ransomware, Wiper

Post navigation

Previous Post: Red Teaming AI: The Build Vs Buy Debate
Next Post: Threat Actors Using Fake Travel Websites to Infect Users’ PCs with XWorm Malware

Related Posts

Surge in Cyberattacks Targeting Journalists: Cloudflare Security Week News
Intel Employee Data Exposed by Vulnerabilities Security Week News
Threat Actor Connected to Play, RansomHub and DragonForce Ransomware Operations Security Week News
SonicWall Hunts for Zero-Day Amid Surge in Firewall Exploitation Security Week News
Zero Networks Raises $55 Million for Microsegmentation Solution Security Week News
200,000 Harbin Clinic Patients Impacted by NRS Data Breach Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Kimsuky Hackers Attacking Users via Weaponized QR Code to Deliver Malicious Mobile App
  • Operation ForumTrol Known for Exploiting Chrome 0-Day Attacking Users With New Phishing Campaign
  • SonicWall Fixes Actively Exploited CVE-2025-40602 in SMA 100 Appliances
  • Kimwolf Botnet Hijacks 1.8 Million Android TVs, Launches Large-Scale DDoS Attacks
  • 5 SOC Analyst Tips for Super-Fast Triage 

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Kimsuky Hackers Attacking Users via Weaponized QR Code to Deliver Malicious Mobile App
  • Operation ForumTrol Known for Exploiting Chrome 0-Day Attacking Users With New Phishing Campaign
  • SonicWall Fixes Actively Exploited CVE-2025-40602 in SMA 100 Appliances
  • Kimwolf Botnet Hijacks 1.8 Million Android TVs, Launches Large-Scale DDoS Attacks
  • 5 SOC Analyst Tips for Super-Fast Triage 

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2025 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark