Activity timeline
Anubis appears in 3 tracked threats between and ; the busiest month was 2026-07 with 2 reports.
ATT&CK techniques observed
- T1005 Data from Local System — Collectionobserved in 3 of 3 tracked threats
- T1078 Valid Accounts — Initial Accessobserved in 3 of 3 tracked threats
- T1133 External Remote Services — Initial Accessobserved in 3 of 3 tracked threats
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 3 of 3 tracked threats
- T1485 Data Destruction — Impactobserved in 3 of 3 tracked threats
- T1489 Service Stop — Impactobserved in 3 of 3 tracked threats
- T1490 Inhibit System Recovery — Impactobserved in 3 of 3 tracked threats
- T1021.001 Remote Desktop Protocol — Lateral Movementobserved in 2 of 3 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 2 of 3 tracked threats
- T1112 Modify Registry — Defense Impairmentobserved in 2 of 3 tracked threats
- T1486 Data Encrypted for Impact — Impactobserved in 2 of 3 tracked threats
- T1566.001 Phishing: Spearphishing Attachment — Initial Accessobserved in 2 of 3 tracked threats
- T1572 Protocol Tunneling — Command and Controlobserved in 2 of 3 tracked threats
- T1685 Disable or Modify Tools — Defense Impairmentobserved in 2 of 3 tracked threats
- T1685.005 Clear Windows Event Logs — Defense Impairmentobserved in 2 of 3 tracked threats
Tracked threats
- City of Coweta, Oklahoma Hit by Anubis Ransomware AttackHIGH
- Anubis Ransomware Encrypts Nutanix Systems and Exfiltrates 1TB from Coca-Cola's Fairlife Dairy Subsidiary, Halting US ProductionHIGH
- Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and Kontron Driver BYOVD for Access and Privilege EscalationCRITICAL