Anubis Ransomware Uses File Wiper in Attacks
Anubis Ransomware Uses File Wiper in Attacks

Anubis Ransomware Uses File Wiper in Attacks

News summary

The Anubis ransomware-as-a-service (RaaS) operation has emerged with a dual-threat model that combines traditional data encryption with a file-wiping feature activated via a '/WIPEMODE' command, making recovery impossible even if a ransom is paid. Trend Micro researchers report that Anubis amplifies extortion pressure by sabotaging victims' recovery efforts post-encryption. The group targets sectors such as construction, engineering, and healthcare across several countries, gaining initial access primarily through spear phishing and employing advanced privilege escalation and file discovery techniques. Analysts note that Anubis's affiliate model enables rapid expansion and sophisticated monetization among cybercriminals. Security experts advise organizations to maintain offline and immutable backups to defend against such destructive ransomware. This escalation reflects the broader trend of ransomware actors adopting more destructive and innovative strategies.

Story Coverage
Bias Distribution
100% Center
Information Sources
68e7fc5e-537b-4887-b796-fbd29c315618
Center 100%
Coverage Details
Total News Sources
1
Left
0
Center
1
Right
0
Unrated
0
Last Updated
1 day ago
Bias Distribution
100% Center
Related News
Daily Index

Negative

29Serious

Neutral

Optimistic

Positive

Ask VT AI
Story Coverage
Subscribe

Stay in the know

Get the latest news, exclusive insights, and curated content delivered straight to your inbox.

Present

Gift Subscriptions

The perfect gift for understanding
news from all angles.

Related News
Recommended News