Anubis is a ransomware-as-a-service (RaaS) operation active in 2025 and 2026 that uses an affiliate model rather than a single uniform intrusion set. Reported victimology indicates broad, opportunistic targeting across multiple sectors and geographies, including healthcare, manufacturing, telecommunications, energy, construction, financial services, engineering, legal and business services, with observed victims in the United States, United Kingdom, France, Germany, and Switzerland. Multiple incidents attributed to Anubis involved both encryption-driven disruption and associated data theft or exposure, consistent with modern double-extortion ransomware operations. Observed tradecraft shows recurring abuse of VPN infrastructure for initial access. Documented intrusion activity includes exploitation of CitrixBleed 2 (CVE-2025-5777) against Citrix VPN infrastructure, as well as use of external remote services. After compromise, Anubis affiliates have been observed relying on legitimate remote monitoring and management software, living-off-the-land techniques, and security-evasion behavior. ATT&CK techniques associated with reported Anubis activity include Exploit Public-Facing Application (T1190), External Remote Services (T1133), Remote Access Software (T1219), and System Binary Proxy Execution (T1218). Anubis has also been linked to criminal support infrastructure used by ransomware operators. Blockchain tracing cited in sanctions-related reporting showed direct payments from Anubis to FirstVPN, a VPN service later sanctioned by the U.S. Treasury for enabling ransomware and other cybercriminal activity. This connection indicates Anubis operators or affiliates procured anonymizing infrastructure from services marketed to cybercriminals. Available reporting supports characterizing Anubis as a financially motivated cybercriminal ransomware operation. No high-confidence attribution to a nation-state is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
15 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named ransomware group that directly paid FirstVPN for operational infrastructure.
Conducting a ransomware attack resulting in a data breach and exposure of law firm clients’ personal data.
Conducting a ransomware attack resulting in a data breach affecting Surtifamiliar, with stolen data described as passports of supermarket chain employees.
Conducting a ransomware attack resulting in exposure of orthopedic clinic patients’ data and medical records.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.