Anubis Ransomware Encrypts Nutanix Systems and Exfiltrates 1TB from Coca-Cola's Fairlife Dairy Subsidiary, Halting US Production — Threadlinqs Intelligence
As of 2026-07-22, Anubis Ransomware Encrypts Nutanix Systems and Exfiltrates 1TB from Coca-Cola's Fairlife Dairy Subsidiary, Halting US Production is a high-severity ransomware threat attributed to Anubis, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-1615 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: Anubis · FINANCIAL
The Anubis ransomware-as-a-service (RaaS) group compromised Coca-Cola's dairy subsidiary fairlife around July 9-13, 2026, encrypting Fairlife's Nutanix hyperconverged infrastructure and claiming
On or around July 9-13, 2026, the Anubis ransomware-as-a-service operation gained unauthorized access to systems belonging to fairlife, LLC, the ultra-filtered milk and protein-shake dairy subsidiary of The Coca-Cola Company. Anubis claims to have fully encrypted Fairlife's Nutanix hyperconverged infrastructure and to have exfiltrated approximately 1TB of confidential corporate data prior to encryption, consistent with Anubis's standard double-extortion playbook of staging and exfiltrating data before triggering its Go-based encryptor. Coca-Cola disclosed the incident on July 16, 2026, stating a third party gained unauthorized entry to systems related to Fairlife production, that production quality/safety was not impacted, that external cybersecurity experts and law enforcement/authorities were engaged, and that US dairy production was suspended while Canadian fairlife production continued normally. Anubis added fairlife to its dark-web data leak site on July 20-21, 2026, publicly claiming the attack, stating victims did not follow negotiation instructions left on the network, and threatening to publish the stolen 1TB unless a ransom is paid within roughly one week of listing, claiming it can restore encrypted systems "within hours" upon payment.
Anubis (RaaS, first observed December 2024 under the codename 'Sphinx', rebranded to Anubis in February 2025) is a Go-language, cross-platform (Windows/Linux/NAS/ESXi) ransomware family notable for combining conventional ECIES (Elliptic Curve Integrated Encryption Scheme, via the github.com/ecies/go library) hybrid file encryption with an optional destructive '/WIPEMODE' feature that overwrites file contents down to 0 KB, permanently destroying data even if a decryption key is later supplied or paid for. The group operates a tiered affiliate program (80/20 RaaS split, 60/40 data-extortion split, 50/50 access-monetization split), has listed roughly 94 victims as of July 20, 2026, primarily in the US, Australia, Canada, Western Europe, and Latin America, concentrated in healthcare, business services, manufacturing, hospitality, and construction, while explicitly excluding CIS countries, government, education, and non-profits. Attribution assessments point to Russian-speaking, CIS-timezone-aligned operators using aliases including 'superSonic' (RAMP forum) and 'Anubis__media' (XSS forum).
The malware's typical attack chain begins with spear-phishing (malicious attachments/links), exposed RDP, pre-existing malware loaders, or trojanized software updates for initial access. Post-compromise, the encryptor performs stealthy privilege checks by attempting to open a raw disk device handle (\\.\PHYSICALDRIVE0) rather than calling noisy Windows APIs like IsUserAnAdmin(), supports token manipulation/re-execution via an '/elevated' flag, conducts filesystem discovery excluding system and developer-tool directories (Windows, System32, Program Files, ProgramData, AppData, .nuget, .gradle, .vscode, efi, boot), and — where lateral movement has been observed — stages and exfiltrates data prior to encryption. Before encrypting, the payload terminates over 90 processes/services spanning SQL Server, backup software (Veeam, Acronis, BackupExec), and endpoint security products (Sophos, Symantec, Windows Defender components), then deletes Volume Shadow Copies via `vssadmin delete shadows /for=norealvolume /all /quiet`. Encrypted files receive the `.anubis` extension, a `RESTORE FILES.html` ransom note is dropped into affected directories, and the desktop wallpaper is changed via a registry modification referencing dropped icon/wallpaper assets in C:\ProgramData. When the destructive `/WIPEMODE` parameter is invoked, targeted files are irreversibly reduced to 0 KB in place of (or in addition to) encryption, removing any possibility of recovery regardless of ransom payment — a capability directly relevant to the Fairlife incident given the group's claim of full Nutanix-system encryption and its history of us
Target sectors: food-and-beverage, manufacturing, health, business-services, hospitality, construction
Target regions: united states of america, canada, australia, 155 - Western Europe, Latin America, Asia-Pacific
Detections & IOCs
As of 2026-07-22, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1566.001, T1190, T1133, T1059, T1059.003, T1078, T1134.001, T1548, T1562.001, T1112