Anubis is a ransomware-as-a-service group active since December 2024, known for targeting healthcare, engineering, and construction sectors.
Analyst brief
Anubis is a ransomware-as-a-service group active since December 2024, targeting sectors such as healthcare, engineering, construction, and professional services. It also poses threats to other sectors including manufacturing, retail & e-commerce, financial services, and technology across the United States, France, United Kingdom, Colombia, Switzerland, and Germany. Its key TTPs involve standard encryption along with an optional destructive "wipe mode," while offering affiliates a flexible revenue split model. Defenders should prioritize monitoring for suspicious network activities, phishing campaigns, and the deployment of ransomware tools, especially in critical infrastructure and data-sensitive environments.
anubis
activecrime
Anubis is a ransomware-as-a-service group active since December 2024 that targets healthcare, engineering, construction, and professional services sectors, offering affiliates a flexible revenue split model and an optional destructive "wipe mode" alongside standard encryption.
Which sectors does the Anubis ransomware group primarily target?+
Anubis primarily targets the healthcare, engineering, construction, and professional services sectors, but it can also attack manufacturing, retail, financial services, and technology sectors.
What are the key TTPs of the Anubis ransomware group?+
Anubis' key TTPs include standard encryption along with an optional 'wipe mode', and it offers affiliates a flexible revenue split model.