A dangerous upgrade has been detected in the functionality of Anubis, a new ransomware-as-a-service (RaaS), as a destructive wiper. With this new capability, the attack goes beyond simply encrypting files, but completely destroys, nullifying any possibility of recovery — even if a ransom is paid.
Anubis, which is not related to the Android malware of the same name, made its appearance in December 2024 and has been showing increased activity since early 2025. Its official entry into the cybercrime ecosystem took place on February 23, when its creators announced an affiliate program on the well-known RAMP forum.
According to an analysis by KELA, the Anubis ransomware collaboration model is particularly tempting for cybercriminals: ransomware partners receive 80% of the malicious enterprises' revenue, extortionists 60% and initial access brokers 50%.
See also: Fog ransomware attack uses open source tools

Although the official blackmail page on the dark web currently lists only eight victims, experts estimate that this number could increase rapidly as the technological credibility of the platform strengthens.
A recent Trend Micro report reveals that the Anubis developers are constantly evolving the malware's capabilities , with the wiper module standing out as the most worrying innovation. Analysts believe this is a pressure strategy , aimed at accelerating the ransom payment , preventing any attempts at delay or negotiation.
"This approach intensifies the psychological pressure on victims and significantly increases the risks of an already serious cyberattack," the report states.
The wiper function is activated with the /WIPEMODE on the command line and requires authentication via a key to take effect. When executed, it deletes the contents of files , reducing their size to 0 KB, while at the same time keeping the structure and names of the files intact. The result is highly misleading: the victim sees the files in their place, but their contents are permanently lost, with no possibility of recovery.
See also: Sensata Technologies: Ransomware attack led to data breach
Additionally, Anubis ransomware supports a wide range of commands at startup, including functions to escalate privileges, exclude specific folders from attack, and set targets for encryption.
In a sign of technical maturity, the creators of Anubis have foreseen the exclusion of critical system directories and essential applications to ensure the continued operation of the system after the attack – a tactic that allows the ransom message to appear without a complete collapse of the environment.
The malware also deletes Volume Shadow Copies and terminates processes and services that may interfere with encryption.
As for the encryption process, Anubis ransomware uses the ECIES (Elliptic Curve Integrated Encryption Scheme) protocol. Encrypted files are given the .anubis extension , while an HTML file with a ransom note is placed in the relevant folders. In addition, the malware attempts to change the desktop wallpaper, although this operation seems to fail.
See also: FBI: Play ransomware has compromised 900 organizations
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Anubis is primarily introduced via phishing emails containing malicious links or attachments. Trend Micro has published detailed indicators of compromise (IoCs) for those looking to detect or prevent a potential infection.
Ransomware protection
- Stay up to date on the latest ransomware trends and tactics used by attackers
- Implement multi-factor authentication (MFA) for all user accounts
- Enable firewall on all devices connected to your network
- Keep sensitive data encrypted
- Update all your devices and systems with the latest security patches
- Conduct regular security audits and penetration testing
- Use strong, unique passwords and change them regularly.
- Limit user access to only necessary systems and information
- Consider using solutions email security for additional protection against phishing attacks
- Have a recovery plan to quickly restore systems in the event of an attack
- Enable the display of file extensions
- Invest in advanced protection solutions
- Use sandboxing for email attachments
- Keep backup copies of your data
Source: www.bleepingcomputer.com
