Anubis and Nova Expand Their Ransomware Campaigns, New Victims Raise Fresh Cybersecurity Concerns + Video

Listen to this Post

Featured ImageIntroduction: Another Day, Another Warning From the Ransomware Underground

The ransomware landscape continues to evolve at an alarming pace, with cybercriminal groups aggressively targeting organizations across multiple industries and countries. Every newly published victim on a ransomware leak site serves as another reminder that digital extortion remains one of the most profitable forms of cybercrime. While public claims made by ransomware operators should always be approached with caution until independently verified, they provide valuable insight into the ongoing activities of threat actors and the sectors they appear to be targeting.

On July 20, 2026, threat intelligence monitoring identified two separate ransomware announcements involving the Anubis and Nova ransomware groups. According to publicly observed dark web activity reported by ThreatMon’s Threat Intelligence Team, Bath Fitter and Universidad Nacional de Mar del Plata were added to the respective victim lists of these ransomware operations. Although these announcements do not automatically confirm a successful compromise or data breach, they deserve attention from defenders monitoring the constantly shifting ransomware ecosystem.

Threat Intelligence Summary

ThreatMon researchers observed new ransomware-related activity on July 20, 2026, involving two different threat actors operating within the cybercriminal ecosystem.

The first announcement involved the Anubis ransomware group, which claimed Bath Fitter as one of its newest victims.

Shortly afterward, a second announcement appeared from the Nova ransomware group, alleging that Universidad Nacional de Mar del Plata had also become one of its targets.

At the time of publication, these claims originate from ransomware operators themselves through dark web channels. Independent confirmation from the alleged victims has not yet been publicly established, meaning the claims should currently be treated as allegations until verified through official statements or forensic investigations.

Understanding the Growing Pattern

Ransomware groups frequently publish victim names before releasing evidence or stolen data. This strategy serves several purposes.

First, it creates public pressure on organizations by attracting media attention.

Second, it increases psychological pressure during ransom negotiations.

Finally, it demonstrates the activity of the ransomware group to potential affiliates within the underground ecosystem.

Whether or not negotiations are underway, public leak site announcements have become a standard part of modern double-extortion operations.

Bath Fitter Becomes a Newly Claimed Victim

Bath Fitter is widely recognized for its bathroom remodeling and renovation services. Organizations operating within construction, manufacturing, and home improvement industries often manage sensitive customer records, supplier information, financial documents, and internal business communications.

If a ransomware incident were ultimately confirmed, attackers could potentially pursue both operational disruption and data extortion. However, no verified technical details regarding the alleged incident have been released publicly at this stage.

University Sector Remains Under Pressure

The Nova ransomware

Universities typically operate large and decentralized IT environments containing thousands of endpoints, research systems, student portals, faculty accounts, administrative databases, and collaborative platforms.

This broad attack surface makes higher education an attractive target for financially motivated cybercriminals seeking valuable intellectual property or sensitive personal information.

How Modern Ransomware Operations Function

Today’s ransomware organizations rarely rely solely on file encryption.

Instead, most groups perform multiple stages during an attack, including:

Initial network compromise.

Privilege escalation.

Credential harvesting.

Lateral movement.

Data discovery.

Large-scale data exfiltration.

Encryption of critical systems.

Publication threats through leak portals.

This double-extortion model significantly increases pressure on victims because organizations risk both operational downtime and public exposure of confidential information.

Why Public Claims Require Verification

Threat intelligence platforms routinely monitor ransomware leak sites because they often provide early indicators of ongoing campaigns.

However, cybercriminal groups have occasionally exaggerated or fabricated victim claims to increase publicity.

For that reason, every public ransomware announcement should be evaluated alongside:

Official company statements.

Digital forensic investigations.

Independent cybersecurity reporting.

Regulatory disclosures.

Confirmed evidence of stolen information.

Until multiple sources confirm an incident, responsible reporting should distinguish between a ransomware group’s claim and verified compromise.

Impact on Organizations Worldwide

The continuing appearance of new victims demonstrates that ransomware remains one of the most active cyber threats globally.

Organizations of every size continue facing risks from:

Unpatched vulnerabilities.

Compromised credentials.

Phishing campaigns.

Third-party supply chain exposure.

Misconfigured remote access services.

Insider threats.

Even organizations with mature cybersecurity programs must continuously improve detection, incident response, backup strategies, and employee awareness.

What Undercode Say:

The latest announcements from Anubis and Nova reinforce an important reality about today’s ransomware ecosystem. Modern cybercrime is no longer driven by isolated hackers but by organized criminal enterprises operating with business-like efficiency.

These groups compete for reputation.

They advertise successful attacks.

They recruit affiliates.

They continuously evolve their malware.

Publishing victim names has become part of their marketing strategy.

From an intelligence perspective, these announcements are valuable indicators rather than confirmed evidence.

Security teams should immediately begin monitoring:

• Newly disclosed Indicators of Compromise (IOCs).

• Suspicious outbound network traffic.

• Authentication anomalies.

• Large archive creation.

• Privilege escalation attempts.

• Unexpected PowerShell execution.

• Remote administration utilities.

• RDP activity.

• VPN authentication logs.

• DNS anomalies.

Organizations within construction and education should review their exposure because similar organizations often share comparable technology stacks and security weaknesses.

Defenders should also remember that ransomware attacks rarely begin with encryption.

Most successful incidents spend days or weeks inside networks performing reconnaissance.

Earlier detection remains the most effective defense.

Network segmentation continues to reduce attacker movement.

Immutable backups remain essential.

Multi-factor authentication should be enforced across privileged accounts.

Continuous vulnerability management must remain a priority.

Threat hunting should focus on persistence mechanisms rather than ransomware payloads alone.

Executive leadership should regularly review incident response plans.

Legal teams should understand breach notification obligations.

Communication teams should prepare crisis messaging before incidents occur.

Security awareness training should evolve alongside phishing techniques.

Third-party vendors deserve equal security scrutiny.

Attack surface management should become continuous rather than periodic.

Cyber resilience is increasingly becoming more important than prevention alone.

Organizations should assume that intrusion attempts are inevitable and design security controls capable of detecting adversaries before business-critical systems become encrypted.

Deep Analysis

The following Linux commands can assist defenders during threat hunting and incident response after suspected ransomware activity:

lastlog
who
w
ss -tulnp
netstat -plant
lsof -i
ps aux --sort=-%cpu
pstree -p
journalctl -xe
journalctl --since "24 hours ago"
find / -perm -4000
find / -name ".sh"
find / -mtime -2
find / -type f -size +100M
crontab -l
systemctl list-units --type=service
systemctl list-timers
grep "Failed password" /var/log/auth.log
grep "Accepted password" /var/log/auth.log
ausearch -m USER_LOGIN
sha256sum suspicious_file
rpm -Va
debsums -s

These commands help investigators identify unusual services, unauthorized logins, suspicious scheduled tasks, recently modified files, privilege escalation attempts, abnormal network connections, and indicators that may reveal attacker persistence before or after ransomware deployment.

✅ ThreatMon publicly reported observing ransomware leak-site activity involving the Anubis and Nova groups on July 20, 2026.

✅ The appearance of an organization on a ransomware leak site does not independently confirm that a successful compromise or data theft has occurred.

✅ At the time reflected in the source material, no independently verified public evidence accompanied these claims, so they should be treated as allegations until confirmed by the affected organizations or trusted investigators.

Prediction

(-1)

Ransomware groups are likely to continue publicly naming victims as part of psychological pressure and double-extortion campaigns.

Educational institutions and organizations managing large volumes of customer information will likely remain attractive targets due to their extensive digital infrastructure.

Defenders can expect increased emphasis on credential theft, data exfiltration, and stealthy network persistence before ransomware encryption is deployed, making early detection capabilities more critical than ever.

▶️ Related Video (82% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.stackexchange.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube