By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Anubis Ransomware Encrypts and Wipes Files, Making Recovery Impossible Even After Payment
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Anubis Ransomware Encrypts and Wipes Files, Making Recovery Impossible Even After Payment
Tech News

Anubis Ransomware Encrypts and Wipes Files, Making Recovery Impossible Even After Payment

By Viral Trending Content 4 Min Read
Share
SHARE

Jun 16, 2025Ravie LakshmananMalware / Ransomware

An emerging ransomware strain has been discovered incorporating capabilities to encrypt files as well as permanently erase them, a development that has been described as a “rare dual-threat.”

“The ransomware features a ‘wipe mode,’ which permanently erases files, rendering recovery impossible even if the ransom is paid,” Trend Micro researchers Maristel Policarpio, Sarah Pearl Camiling, and Sophia Nilette Robles said in a report published last week.

The ransomware-as-a-service (RaaS) operation in question is named Anubis, which became active in December 2024, claiming victims across healthcare, hospitality, and construction sectors in Australia, Canada, Peru, and the U.S. Analysis of early, trial samples of the ransomware suggests that the developers initially named it Sphinx, before tweaking the brand name in the final version.

Cybersecurity

It’s worth noting that the e-crime crew has no ties to an Android banking trojan and a Python-based backdoor of the same name, the latter of which is attributed to the financially-motivated FIN7 (aka GrayAlpha) group.

“Anubis runs a flexible affiliate program, offering negotiable revenue splits and supporting additional monetization paths like data extortion and access sales,” the cybersecurity company said.

The affiliate program follows an 80-20 split, allowing affiliate actors to take 80% of the ransom paid. On the other hand, data extortion and access monetization schemes offer a 60-40 and 50-50 split, respectively.

Attack chains mounted by Anubis involve the use of phishing emails as the initial access vector, with the threat actors leveraging the foothold to escalate privileges, conduct reconnaissance, and take steps to delete volume shadow copies, before encrypting files and, if necessary, wipe their contents.

This means that the file sizes are reduced to 0 KB while leaving the file names or their extensions untouched, making recovery impossible and, therefore, exerting more pressure on victims to pay up.

“The ransomware includes a wiper feature using /WIPEMODE parameter, which can permanently delete the contents of a file, preventing any recovery attempt,” the researchers said.

“Its ability to both encrypt and permanently destroy data significantly raises the stakes for victims, amplifying the pressure to comply — just as strong ransomware operations aim to do.”

The discovery of Anubis’ destructive behavior comes as Recorded Future detailed new infrastructure associated with the FIN7 group that’s being used to impersonate legitimate software products and services as part of a campaign designed to deliver NetSupport RAT.

Cybersecurity

The Mastercard-owned threat intelligence firm said it identified three unique distribution vectors over the past year that have employed bogus browser update pages, fake 7-Zip download sites, and TAG-124 (aka 404 TDS, Chaya_002, Kongtuke, and LandUpdate808) to deliver the malware.

While the fake browser update method loads a custom loader dubbed MaskBat to execute the remote access trojan, the remaining two infection vectors employ another custom PowerShell loader dubbed PowerNet that decompresses and executes it.

“[MaskBat] has similarities to FakeBat but is obfuscated and contains strings linked to GrayAlpha,” Recorded Future’s Insikt Group said. “Although all three infection vectors were observed being used simultaneously, only the fake 7-Zip download pages were still active at the time of writing, with newly registered domains appearing as recently as April 2025.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Google Chrome Zero-Day CVE-2025-2783 Exploited by TaxOff to Deploy Trinper Backdoor

Dublin’s Mater hospital opens AI hub to drive innovation in patient care

Next iPad Mini Rumors: Features, Specs, and Release Date

Nintendo Switch 2 Review: The Next-Gen Upgrade You’ve Been Waiting For

How Private Equity Killed the American Dream

TAGGED: Cyber Security, Cybersecurity, Data Wiping, FIN7, healthcare, Internet, Malware, phishing, Ransomware, ransomware-as-a-service, Recorded Future, Remote Access Trojan, Threat Intelligence, Trend Micro
Share This Article
Facebook Twitter Copy Link
Previous Article Verifying the authenticity of videos claiming to show Israeli and Iranian airstrikes
Next Article Polyhedra’s ZKJ token collapses following ‘abnormal on-chain activity’
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

XRP price holds above $2 as SEC delays Franklin Templeton XRP ETF
Crypto
40 hours of violence and fear as gunman stalks Minnesota politicians
Politics
15 beginner’s tips before you start FBC: Firebreak
Gaming News
Texas Bitcoin Reserve Law Triggers Sunday—Silence Means Yes
Crypto
Google Chrome Zero-Day CVE-2025-2783 Exploited by TaxOff to Deploy Trinper Backdoor
Tech News
More Safeway, Albertsons workers authorize strike; negotiations set to resume
Business
XRP price prediction: analyst sees 500% breakout as charts mirror 2017 rally
Crypto

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

XRP price holds above $2 as SEC delays Franklin Templeton XRP ETF

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
XRP price holds above $2 as SEC delays Franklin Templeton XRP ETF
June 18, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?