2 min read

Anubis's real innovation isn't the ransomware — it's making destruction irreversible- 250

Anubis's real innovation isn't the ransomware — it's making destruction irreversible- 250

July 1, 2026

Anubis, a ransomware-as-a-service operation that emerged in late 2024 as a spinoff of the Sphinx ransomware family, has claimed 91 victims on its leak site to date, including 11 in June 2026 alone. But the detail that should worry defenders more than the victim count is a single module called WIPEMODE — a feature that decouples destruction from payment entirely, turning ransomware's traditional negotiating logic upside down by making the damage irreversible the moment it activates, whether or not the ransom is ever paid.

Rubrik Zero Labs, which documented the group's business model in a July 2025 report, describes WIPEMODE in stark terms: once activated, targeted files remain visible in their original directories but are reduced to zero kilobytes in size, regardless of whether the victim subsequently pays. That single design choice restructures the entire economics of the extortion threat. Conventional ransomware negotiations rest on an implicit promise that payment restores access — a promise that, however cynically honored in practice, gives victims some rational basis for paying. WIPEMODE removes that promise structurally: a threat actor can revert a victim's environment to what Rubrik calls a scorched-earth state with a single command, and no subsequent payment reverses it. That shift, Rubrik argues, creates a powerful incentive for motivated affiliates to specifically choose Anubis over competing ransomware brands, precisely because the threat of irreversible destruction pressures victims to pay before the wiper activates, rather than during the more familiar back-and-forth of a conventional ransom negotiation.

Anubis backs that psychological leverage with an unusually generous affiliate structure — an 80 percent profit split, among the more favorable terms in the current RaaS market, which likely explains the group's rapid growth since its February 2025 disclosure on the RAMP darkweb forum. The victim profile skews heavily toward the United States, which accounts for more than half of documented targets, followed by the UK, Australia, France, and Canada, concentrated across business services, technology, financial services, and healthcare. Initial access in 2026's incidents has combined exploitation of CVE-2025-5777, a severe Citrix NetScaler vulnerability carrying a 9.3 CVSS score, alongside valid VPN credentials whose origin remains unclear — researchers suspect they're gathered through post-compromise credential harvesting, credential stuffing, initial access brokers, or information-stealer malware operating independently of Anubis itself.

Once inside a network, Arctic Wolf's tracking of the group's tradecraft reveals a deliberately camouflaged operational style: rather than deploying custom remote-access tooling that might trigger security alerts, affiliates repurpose entirely legitimate IT administration software — MeshAgent, Total Software Deployment, ScreenConnect, UltraVNC, and Zoho Assist — to maintain control of compromised systems while blending seamlessly into an organization's ordinary remote-support traffic. Arctic Wolf notes that specific techniques vary meaningfully across different affiliates, a natural consequence of the RaaS model's decentralized structure, but the shared throughline across nearly every intrusion is hands-on-keyboard activity and credential access carried out through tools a defender's own IT team uses every day — meaning the most effective detection signal isn't unusual software appearing on the network, but ordinary software being used in unusual ways.