Ransomware Group intelligence
Anubis
ActiveTrack Anubis with 132 published victims and 3 known leak locations in a single intelligence view.
Overview
Anubis is tracked by Breach House as a ransomware group with 132 published victims.
United States is currently the most targeted country in this dataset.
3 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (3)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 2h ago | om6q4a6cyipxvt7ioudxt24cw4oqu4yodmqzl25mqd2hgllymrgu4aqd.onion |
| Leak location 3 | Onion service | Up checked 2h ago | 6g3aoky5hft4mvzcqt2bugo4r465woaorjhd7em2k2v24sr2exaro5id.onion |
| Leak location 2 | Onion service | Down checked 2h ago | anubisyfkh5rixydjpoo3jqucauajz2juybrbtuglcppjj2y3eg3y6ad.onion |
Top Activity Sectors (16)
- Healthcare / Pharma 30
- Finance / Legal / Insurance 20
- Not identified 13
- Manufacturing / Engineering 7
- Construction / Real Estate 7
- IT 7
- Communication / Marketing 5
- Transportation / Travel / Logistics 4
- Agriculture / Food 3
- NGOs / Associations 2
- Energy 2
- Hospitality / Food & Beverage / Tourism 2
- Public Sector 2
- Retail / E-commerce 1
- Telecommunications 1
- Services 1
Typical Attacks (12)
▼MITRE ATT&CK does not currently catalogue Anubis, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: anubis executes PowerShell scripts to stage payloads and manipulate system processes during initial compromise.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1569.002 Service Execution Execution
What they do: anubis executes malicious binaries through service contexts to maintain persistence and evade user interaction.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
What they do: anubis modifies registry run keys to ensure malware reactivation after system reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: anubis disables security tools like EDR and firewalls to prevent detection and hinder incident response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.016 Junk Code Insertion Stealth
What they do: anubis injects junk code into legitimate binaries to evade static analysis and behavioral detection.
What that means: Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
-
T1070.004 File Deletion Stealth
What they do: anubis deletes Volume Shadow Copies and backup directories to eliminate recovery options for victims.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: anubis leverages remote system discovery to identify additional hosts within the victim network for lateral movement.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1057 Process Discovery Discovery
What they do: anubis uses process discovery to identify critical services and isolate targets for disruption.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1135 Network Share Discovery Discovery
What they do: anubis scans network shares to map victim infrastructure and identify high-value data repositories.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1486 Data Encrypted for Impact Impact
What they do: anubis encrypts victim files using custom symmetric encryption routines to maximize impact and extortion leverage.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: anubis stops critical Windows services and kills processes to cripple victim operations before encryption.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: anubis triggers system shutdown commands and service termination to disrupt operational continuity.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
DATA_BREACH_[victim].txt
Good afternoon, [snip]! This is the ANUBIS hacker team. We want to let you know that we have been on your network for a long time and have been studying your company's business. We have downloaded gigabytes of your data, which is now being analyzed by our best experts. Contact us and we will provide you with a list of files that we have. If we can't reach an agreement, we will notify every customer of the data leak. If you ignore or refuse the deal, we will be forced to publish all your data in the public domain. As our blog grows and attracts media attention every day, the case will become publicized and cause devastating damage to your business. The only way to avoid this is to make a deal with us. Appoint a responsible person to negotiate and get down to business. Otherwise, every client will see how you disregarded their personal information and will have a detailed plan on how to win a case against you in court. To contact us and resolve this issue, you need to access us via TorBrowser (https://www.torproject.org/download/). We regularly send you a chat link and your credentials through your website. You will need to act strictly according to the instructions. In addition, we have sent you confirmation that we hold all your data. Then go to our website: 6g3aoky5hft4mvzcqt2bugo4r465woaorjhd7em2k2v24sr2exaro5id.onion And enter your unique ID: [snip] I also recommend visiting our blog via the Tor browser, there, we post files from companies that refuse to pay. The same fate awaits you if we don�t reach an agreement. Our blog is followed by the global media. http://om6q4a6cyipxvt7ioudxt24cw4oqu4yodmqzl25mqd2hgllymrgu4aqd.onion
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (132)
Search, filter and paginate the victim timeline for Anubis. Showing 101–132 of 132.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Fun For Less Tours id24321 View details | United States | Other | ||
|
Customer passports and personal data. |
|||||
| Ransomware | Mid South Pulmonary & Sleep Specialists id24280 View details | United States | Healthcare / Pharma | ||
|
Patient data breach. |
|||||
| Ransomware | AllerVie Health id24220 View details | United States | Healthcare / Pharma | ||
|
Major customer database leak. |
|||||
| Ransomware | FSGROUP-Engineering id23988 View details | Spain | Manufacturing / Engineering | ||
|
Leakage of customer contact details. |
|||||
| Ransomware | Lung Rose Voss Wagnild id23851 View details | United States | Finance / Legal / Insurance | ||
|
Hawaii’s leading law firm data breach. |
|||||
| Ransomware | Brenda Richardson Memorial Care Home LLC id23809 View details | United States | Healthcare / Pharma | ||
|
Negligence of mental health care agency employees |
|||||
| Ransomware | Olive Branch Family Medical Center id23808 View details | United States | Healthcare / Pharma | ||
|
Data Breach at U.S. Medical Center Puts Thousands of Patients at Risk |
|||||
| Ransomware | Dermatology Associates id23647 View details | United States | Healthcare / Pharma | ||
|
Leak of clinic customer data. |
|||||
| Ransomware | Mayco International id23575 View details | United States | Manufacturing / Engineering | ||
|
Data breach at automotive industry leader. |
|||||
| Ransomware | Mayco International [www.maycointernational.com] id23557 View details | United States | Manufacturing / Engineering | ||
|
Data breach at automotive industry leader. |
|||||
| Ransomware | Goodfellow & Schuettlaw id23300 View details | Canada | Finance / Legal / Insurance | ||
|
Personal data, confidential documents, and more. |
|||||
| Ransomware | Paterson & Dowding Family Lawyers id23299 View details | Australia | Finance / Legal / Insurance | ||
|
Law firm data breach |
|||||
| Ransomware | Aussie Fluid Power id23162 View details | Australia | Energy | ||
|
An Australian engineering leader has fallen victim to a cyberattack causing a data breach. |
|||||
| Ransomware | Maine Oxy id22973 View details | United States | Finance / Legal / Insurance | ||
|
Financial data breach |
|||||
| Ransomware | Den Hartogh Logistics id22945 View details | Netherlands | Transportation / Travel / Logistics | ||
|
Data leak at one of the world's leading logistics service providers |
|||||
| Ransomware | One law firm in Canada id22861 View details | Canada | Finance / Legal / Insurance | ||
|
It seems they have decided to play silent. |
|||||
| Ransomware | DRL Group id22696 View details | India | Services | ||
|
Customer data leak |
|||||
| Ransomware | Storage King id22681 View details | Australia | Other | ||
|
Major personal data leak |
|||||
| Ransomware | Alan Shintani, Inc id22502 View details | United States | Communication / Marketing | ||
|
Photos and blueprints of government facilities. |
|||||
| Ransomware | GCC of America, inc. id22087 View details | United States | Communication / Marketing | ||
|
Data breach at one of the largest cement and concrete producers in North America. |
|||||
| Ransomware | TRAF Industrial Products Inc id21991 View details | Canada | Manufacturing / Engineering | ||
|
Data breach at an aerospace and defense contractor. |
|||||
| Ransomware | Grand Rapids Controls id21761 View details | United States | Other | ||
|
The 150 GB leak involves confidential documents and NDA agreements with companies such as Ford, Bentley, Lear, and others. |
|||||
| Ransomware | Advanced HPC id21722 View details | United States | Construction / Real Estate | ||
|
Leakage of internal documents at a company engaged in the development and implementation of HPC systems for science and defence. |
|||||
| Ransomware | Disneyland Paris id20757 View details | France | Other | ||
|
Confidential Disneyland documents. |
|||||
| Ransomware | Parkway Construction LLC id20558 View details | United States | Construction / Real Estate | ||
|
Blueprints of L3Harris, General Atomics and Virgin Galactic. |
|||||
| Ransomware | Two Kings Casino Resort id19317 View details | United States | Hospitality / Food & Beverage / Tourism | ||
|
Leaked ultra-detailed blueprints of a casino that plans a grand opening in 2026. |
|||||
| Ransomware | DG2 Design id18899 View details | United States | Finance / Legal / Insurance | ||
|
Blueprints of M1 Bank, Mastercard and so on. |
|||||
| Ransomware | Ambleside id18627 View details | Healthcare / Pharma | |||
|
Breach of personal data of patients, company employees, and dozens of incidents, including Patient abuse. |
|||||
| Ransomware | Pound Road Medical Centre id17769 View details | Australia | Healthcare / Pharma | ||
|
AU Passports, DOB, Medical Records. |
|||||
| Ransomware | Summit Home Health, INC. id17768 View details | United States | Healthcare / Pharma | ||
|
7000+ US Fullinfo |
|||||
| Ransomware | Comercializadora S&E Perú id17767 View details | Peru | Finance / Legal / Insurance | ||
|
Detailed financial and privacy information. |
|||||
| Ransomware | First Defense Fire Protection id17766 View details | United States | Communication / Marketing | ||
|
Leaked blueprints for casinos, airports and hundreds of other companies. |
|||||