Anubis ransomware adds wiper to destroy files beyond recovery
A wiper module has been introduced to the Anubis ransomware-as-a-service (RaaS) operation's file-encrypting software, which eliminates targeted files and prevents recovery even in the event that the ransom is paid.
Anubis is a relatively new RaaS that was initially discovered in December 2024 but increased in activity at the start of the year. It should not be confused with the same-named Android virus that has a ransomware module.
An affiliate program was announced by the operators on the RAMP forum on February 23. According to a KELA investigation at the time, Anubis gave ransomware affiliates an 80% cut of the money they made. A 60% cut was offered to data extortion associates, while a 50% cut was offered to initial access brokers.
Only eight victims are listed on Anubis' exto...

