What Is Anubis?
Well, Anubis is the ancient Egyptian god of the dead, typically portrayed as a man with the head of a jackal. But for the purposes of this article we're talking about the Anubis ransomware group. The Anubis ransomware-as-a-servie (RaaS) operation first appeared under a different Egyptian-themed name, Sphinx, before rebranding itself in late 2024. Whereas Sphinx appended a ".sphinx" extension to teh end of encrypted files, Anubis adds ".anubis"
So, Is the Anubis Ransomware of Egyptian Origin?
That seems unlikely. Although no regional attribution has been confirmed for the group, researchers have noticed its members making announcements and posts in Russian. However, it would be wrong to assume that everyone connected with Anubis is of Russian origin. Anubis affiliates are offered up to 80% of ransom payments, making it an attractive option for cybercriminals around the world.
What Makes Anubis Unusual?
Most of today's ransomware gangs threaten to publish exfiltrated data if victims do not pay a ransom. Anubis, however, can go a step further. There is an optional "wipe mode" built into its code which can permanently erase a file's contents rather than merely encrypting them. After a file has been through the "wipe mode" process, it shows its size as zero bytes. This irreversible data-wiping payload applies even more pressure on victims to give in to a ransom demand.
In Other Words - You Had Best Have a Reliable Working Backup
Right. It may be old advice, but it's just as important now as it ever was.
So What Type of Organizations Are Being Hit by Anubis?
The healthcare sector appears to have been particularly targeted by Anubis. For instance, the Mississippi-based Singing River Health System had its network compromised by Anubis, and data stolen including contact details, Social Security numbers, dates of birth, IDs, patient treatment details, diagnostic test results, medication lists, bank account information, health insurance numbers and provider names. According to researchers, the Anubis gang claimed to have stolen 293GB of data including intimate surgical images and over 1.2 million files from the hospital group, which cares for over 100,000 patients per year. This was the second major ransomware incident Singing River had suffered in just two years, following an attack by the Rhysida ransomware group in 2023. Beyond healthcare, Anubis targets manufacturing, construction, legal services, and financial services. Of the approximately 90 victims claimed on the group's dark web leak site as of early July 2026, the United States accounts for the largest share, followed by the UK, Australia, France, and Canada.
So How Does Anubis Break into a Company's Network?
Researchers have identified that common paths of entry involve carefully-crafted spear-phishing emails (with malicious attachments or dangerous links) and - most recently - exploitation of the CitrixBleed 2 (CVE-2025-5777) vulnerability that can expose session tokens and allow attackers to bypass multi-factor authentication (MFA). Once inside, hackers spread laterally using legitimate remote management tools to not draw attention to themselves.
What Should My Company Do to Help Protect Itself from Anubis?
Organizations who feel they could be at risk from Anubis would be wise to follow Fortra's general advice for defending against ransomware attacks, which includes tips such as enforcing multi-factor authentication, running up-to-date security solutions, keeping software patches current, and implementing ransomware protection solutions. In addition, it is a good idea to follow the following steps:
- Patch CVE-2025-5777 immediately. The CitrixBleed 2 vulnerability requires no user interaction to exploit. Every unpatched NetScaler appliance is effectively an open door. After patching, terminate all active sessions as per Citrix's guidance.
- Enforce MFA on all remote access. With compromised credentials being a primary entry point, multi-factor authentication makes it harder for an attacker to gain access.
- Know which remote management tools your organization legitimately uses, and monitor for anything else. Rapid deployment of unauthorized remote management tools could be a strong indicator that your systems are compromised.
- Maintain offline, tested backups.
Cybercrime Intelligence Shouldn't Be Siloed
Fortra® experts are dedicated to protecting organizations and the public by delivering the latest insights, data, and defenses to strengthen security against emerging cyber threats.