Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Anubis Ransomware Encrypts and Wipes Files, Making Recovery Impossible Even After Payment

The Hacker News by The Hacker News
June 16, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Jun 16, 2025Ravie LakshmananMalware / Ransomware

An emerging ransomware strain has been discovered incorporating capabilities to encrypt files as well as permanently erase them, a development that has been described as a “rare dual-threat.”

“The ransomware features a ‘wipe mode,’ which permanently erases files, rendering recovery impossible even if the ransom is paid,” Trend Micro researchers Maristel Policarpio, Sarah Pearl Camiling, and Sophia Nilette Robles said in a report published last week.

The ransomware-as-a-service (RaaS) operation in question is named Anubis, which became active in December 2024, claiming victims across healthcare, hospitality, and construction sectors in Australia, Canada, Peru, and the U.S. Analysis of early, trial samples of the ransomware suggests that the developers initially named it Sphinx, before tweaking the brand name in the final version.

Cybersecurity

It’s worth noting that the e-crime crew has no ties to an Android banking trojan and a Python-based backdoor of the same name, the latter of which is attributed to the financially-motivated FIN7 (aka GrayAlpha) group.

“Anubis runs a flexible affiliate program, offering negotiable revenue splits and supporting additional monetization paths like data extortion and access sales,” the cybersecurity company said.

The affiliate program follows an 80-20 split, allowing affiliate actors to take 80% of the ransom paid. On the other hand, data extortion and access monetization schemes offer a 60-40 and 50-50 split, respectively.

Attack chains mounted by Anubis involve the use of phishing emails as the initial access vector, with the threat actors leveraging the foothold to escalate privileges, conduct reconnaissance, and take steps to delete volume shadow copies, before encrypting files and, if necessary, wipe their contents.

This means that the file sizes are reduced to 0 KB while leaving the file names or their extensions untouched, making recovery impossible and, therefore, exerting more pressure on victims to pay up.

“The ransomware includes a wiper feature using /WIPEMODE parameter, which can permanently delete the contents of a file, preventing any recovery attempt,” the researchers said.

“Its ability to both encrypt and permanently destroy data significantly raises the stakes for victims, amplifying the pressure to comply — just as strong ransomware operations aim to do.”

The discovery of Anubis’ destructive behavior comes as Recorded Future detailed new infrastructure associated with the FIN7 group that’s being used to impersonate legitimate software products and services as part of a campaign designed to deliver NetSupport RAT.

Cybersecurity

The Mastercard-owned threat intelligence firm said it identified three unique distribution vectors over the past year that have employed bogus browser update pages, fake 7-Zip download sites, and TAG-124 (aka 404 TDS, Chaya_002, Kongtuke, and LandUpdate808) to deliver the malware.

While the fake browser update method loads a custom loader dubbed MaskBat to execute the remote access trojan, the remaining two infection vectors employ another custom PowerShell loader dubbed PowerNet that decompresses and executes it.

“[MaskBat] has similarities to FakeBat but is obfuscated and contains strings linked to GrayAlpha,” Recorded Future’s Insikt Group said. “Although all three infection vectors were observed being used simultaneously, only the fake 7-Zip download pages were still active at the time of writing, with newly registered domains appearing as recently as April 2025.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Tags: computer securitycyber attackscyber newscyber security newscyber security news todaycyber security updatescyber updatesdata breachhacker newshacking newshow to hackinformation securitynetwork securityransomware malwaresoftware vulnerabilitythe hacker news
The Hacker News

The Hacker News

Next Post
AWS CEO On New B Cloud, AI And Sustainability Investment In Australia

AWS CEO On New $13B Cloud, AI And Sustainability Investment In Australia

Recommended.

Stocks making the biggest moves midday: Apple, Alibaba, Palantir Technologies and more

Stocks making the biggest moves midday: Apple, Alibaba, Palantir Technologies and more

April 14, 2025
Microsoft Build 2025: CEO Nadella Takes Platform, Systems Approach To The ‘Agentic Web’

Microsoft Build 2025: CEO Nadella Takes Platform, Systems Approach To The ‘Agentic Web’

May 21, 2025

Trending.

VIDIZMO Earns Microsoft Solutions Partner Designations for All Three Areas of Azure, Solidifying its Expertise in Delivering AI Solutions

VIDIZMO Earns Microsoft Solutions Partner Designations for All Three Areas of Azure, Solidifying its Expertise in Delivering AI Solutions

June 28, 2025
Tilson Continues to Perform for Clients; Shares Substantial Progress in Chapter 11 Process

Tilson Continues to Perform for Clients; Shares Substantial Progress in Chapter 11 Process

June 27, 2025
OneClik Malware Targets Energy Sector Using Microsoft ClickOnce and Golang Backdoors

OneClik Malware Targets Energy Sector Using Microsoft ClickOnce and Golang Backdoors

June 27, 2025
DHS Warns Pro-Iranian Hackers Likely to Target U.S. Networks After Iranian Nuclear Strikes

DHS Warns Pro-Iranian Hackers Likely to Target U.S. Networks After Iranian Nuclear Strikes

June 23, 2025
Le nombre d’utilisateurs de la 5G-A atteint les dix millions en Chine : Huawei présente le développement de la 5G-A et la valeur de l’IA basée sur des scénarios

Le nombre d’utilisateurs de la 5G-A atteint les dix millions en Chine : Huawei présente le développement de la 5G-A et la valeur de l’IA basée sur des scénarios

June 27, 2025

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio