The Ruthless Rise of Anubis: 2025’s Most Devastating Ransomware Threat

Listen to this Post

Featured Image

A Global Cyber Plague Is Unfolding

In 2025, ransomware attacks are no longer isolated digital

Since its emergence in November 2024, Anubis has evolved into one of the most aggressive and technically advanced ransomware groups operating today. It has already launched targeted attacks on critical sectors including healthcare, construction, and professional services, striking organizations in the United States, France, Australia, and Peru. The group’s tactics reveal a terrifying blend of innovation, brutality, and adaptability, making it one of the most unpredictable and financially motivated cybercrime syndicates on the planet.

Inside the Anubis Phenomenon

The Bitsight report paints a chilling picture of a new ransomware titan. Anubis, though still untraced to any nation-state, has shown signs of Russian-speaking affiliations through its communication on dark web forums. Its operations revolve around a hybrid Ransomware-as-a-Service (RaaS) model, where affiliates receive a lion’s share (80%) of the ransom payouts, while the core group collects 20%. However, this profit-sharing adjusts if the affiliates go beyond encryption and steal data—the more invasive the attack, the higher the Anubis cut, climbing to as much as 50% in some cases. This flexible and profit-maximizing structure has made Anubis a magnet for cybercriminals seeking fast returns.

The group’s new “wipe mode” further escalates its threat. In several reported cases, even after ransoms were paid, Anubis permanently destroyed data—a cold tactic either meant to terrorize or punish victims for dragging their feet in negotiations. Such acts are a departure from typical ransomware behavior, which often focuses on return for payment, not scorched-earth tactics.

Technically, Anubis boasts multi-platform versatility. On Windows systems, it uses phishing emails with poisoned attachments or links to infiltrate networks. Once inside, it escalates privileges, wipes shadow copies, disables system services, and encrypts files using ECIES. Meanwhile, on Android, Anubis transforms into a banking trojan, harvesting credentials through phishing overlays, engaging in screen recording and keylogging, and spreading via SMS. It even locks mobile devices and uploads sensitive user files to its own servers.

The group’s impact is not just theoretical. In November 2024, Anubis launched a devastating attack on a healthcare provider in Victoria, Australia, leaking sensitive patient data—names, contact info, medical histories, and Medicare records—on its dark web leak site. A month later, it hit another healthcare organization in Canada with similar results. These attacks have not only damaged the reputation of these institutions but also exposed thousands of patients to identity theft, extortion, and long-term harm.

Anubis is not just another ransomware gang. Its combination of rapid growth, ruthless targeting, financial flexibility, and technological prowess is pushing the boundaries of what ransomware can achieve in 2025. Security experts warn that if left unchecked, Anubis could set a new, more dangerous standard for global cybercrime.

What Undercode Say:

The Financial Engine Behind Anubis

Anubis is redefining the financial playbook of ransomware. Unlike traditional syndicates that simply encrypt and wait for a payout, Anubis capitalizes on dynamic affiliate incentives. The more damage or leverage an affiliate can generate—be it through exfiltration, data destruction, or direct negotiations—the bigger their share. This decentralized, gamified model attracts not just veteran hackers but a growing army of mid-tier cybercriminals hungry for profit. This “pay-per-damage” scheme is accelerating the group’s reach, efficiency, and malicious innovation.

Multi-Layered Threat Architecture

Technologically, Anubis is a multi-headed beast. On Windows, it combines phishing with advanced post-infiltration tools, targeting system integrity and data recovery mechanisms. By deleting volume shadow copies and disabling services, it ensures maximum disruption. Meanwhile, its ECIES encryption approach enables efficient and irreversible file scrambling. On Android, it shifts roles to become a credential-stealing banking trojan with lateral SMS-based propagation—a sophisticated evolution rarely seen in ransomware hybrids.

Destructive Wipe Mode: Psychological Warfare

One of Anubis’s most chilling features is its destructive “wipe mode”. The group isn’t content with encryption and extortion—it’s willing to erase data permanently, even after payment. This psychological weapon is likely designed to force quicker negotiation decisions, spread panic within targeted organizations, and deter resistance. It also creates uncertainty: victims can no longer trust that payment equals restoration, upending the traditional ransom dynamic.

Geopolitical and Sector Targeting

Anubis has prioritized high-stakes sectors like healthcare and construction, knowing these industries are often under-defended but highly sensitive. The inclusion of Australia, France, the US, Canada, and Peru in their target list suggests a non-random, geopolitically aware strategy. This pattern reflects a level of strategic intelligence typically reserved for state-sponsored actors, further deepening suspicions about its origins and backing.

Evolution Through RaaS

By operating under a RaaS model with high affiliate autonomy, Anubis has decentralized its risk while amplifying its spread. Affiliates can attack without full oversight from core operators, meaning Anubis can expand rapidly without bottlenecking operations. This modular structure increases unpredictability, as tactics may vary based on each affiliate’s skills, goals, or temperament.

Exploiting Mobile Ecosystems

The mobile aspect of Anubis cannot be ignored. Android users, often left out of enterprise-level cybersecurity frameworks, are increasingly vulnerable. Anubis’s use of overlay phishing, keylogging, and even device-locking is a clear shift towards personal digital extortion, indicating that the group is diversifying revenue streams beyond large organizations.

Data as a Weapon

Leaking stolen data isn’t new—but Anubis weaponizes it with timing and volume. By targeting sensitive industries like healthcare, it guarantees maximum public fallout. The group understands that stolen health records or construction plans carry more societal weight than generic financial files, leveraging this to pressure victims into quicker payouts.

Building Trust Among Criminals

Anubis is also unique in its reputation-building on the dark web. By offering transparent profit-sharing and cutting-edge tools, it’s building loyalty among affiliates and growing its criminal ecosystem. This internal trust gives it longevity, scalability, and access to better hacking talent than less-organized groups.

Looking Ahead

Anubis has already proven

🔍 Fact Checker Results:

✅ Bitsight’s 2025 data confirms a 25% rise in ransomware victim disclosures and a 53% growth in leak site activity
✅ Anubis has been linked to confirmed attacks in Australia, Canada, the US, and France across healthcare and construction sectors
❌ There’s no verified state affiliation, but Russian language usage on forums suggests likely Eastern European roots

📊 Prediction:

Anubis will likely expand operations across Asia and South America in the second half of 2025, targeting underprepared critical infrastructure. Expect new attack vectors on IoT and smart medical devices, along with more aggressive data-leaking campaigns intended to influence public opinion and maximize financial pressure. If left unchecked, Anubis could evolve into the blueprint for future ransomware groups aiming to weaponize trust, data, and psychological trauma.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: cyberpress.org
Extra Source Hub:
https://www.pinterest.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon