Anubis Ransomware Encrypts Nutanix Systems and Exfiltrates 1TB from Coca-Cola's Fairlife Dairy Subsidiary, Halting US Production

Anubis Ransomware Encrypts Nutanix Systems and Exfiltrates (TL-2026-1615), also tracked as Anubis Ransomware, is a high-severity ransomware operation, first published 2026-07-22. It is attributed to Anubis with medium confidence, affects fairlife, LLC (The Coca-Cola Company) Fairlife US production and, maps to 25 MITRE ATT&CK techniques (T1003, T1005, T1020), and is covered by 9 detection rules and 24 indicators of compromise.

Key facts for TL-2026-1615

Threat ID
TL-2026-1615
Also known as
Anubis Ransomware, Fairlife Ransomware Attack, Coca-Cola Fairlife Data Breach
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
2026-07-22
Last reviewed
2026-07-22
Attribution
Anubis
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
food-and-beverage, manufacturing, health, business-services, hospitality, construction
Target regions
united states of america, canada, australia, 155 - Western Europe, Latin America, Asia-Pacific
Detection rules
9
Indicators of compromise
24

Malware and tooling in Anubis Ransomware Encrypts Nutanix Systems and Exfiltrates

Malware and tooling: Anubis Ransomware, github.com/ecies/go

The Anubis ransomware-as-a-service (RaaS) group compromised Coca-Cola's dairy subsidiary fairlife around July 9-13, 2026, encrypting Fairlife's Nutanix hyperconverged infrastructure and claiming exfiltration of ~1TB of corporate data. Fairlife suspended US dairy production (Canadian operations unaffected) after Coca-Cola disclosed the incident on July 16, 2026; Anubis listed the victim on its Tor leak site on July 20-21 and threatened to publish the stolen data within one week if a ransom is not paid.

How Anubis Ransomware Encrypts Nutanix Systems and Exfiltrates works

On or around July 9-13, 2026, the Anubis ransomware-as-a-service operation gained unauthorized access to systems belonging to fairlife, LLC, the ultra-filtered milk and protein-shake dairy subsidiary of The Coca-Cola Company. Anubis claims to have fully encrypted Fairlife's Nutanix hyperconverged infrastructure and to have exfiltrated approximately 1TB of confidential corporate data prior to encryption, consistent with Anubis's standard double-extortion playbook of staging and exfiltrating data before triggering its Go-based encryptor. Coca-Cola disclosed the incident on July 16, 2026, stating a third party gained unauthorized entry to systems related to Fairlife production, that production quality/safety was not impacted, that external cybersecurity experts and law enforcement/authorities were engaged, and that US dairy production was suspended while Canadian fairlife production continued normally. Anubis added fairlife to its dark-web data leak site on July 20-21, 2026, publicly claiming the attack, stating victims did not follow negotiation instructions left on the network, and threatening to publish the stolen 1TB unless a ransom is paid within roughly one week of listing, claiming it can restore encrypted systems "within hours" upon payment.

Anubis (RaaS, first observed December 2024 under the codename 'Sphinx', rebranded to Anubis in February 2025) is a Go-language, cross-platform (Windows/Linux/NAS/ESXi) ransomware family notable for combining conventional ECIES (Elliptic Curve Integrated Encryption Scheme, via the github.com/ecies/go library) hybrid file encryption with an optional destructive '/WIPEMODE' feature that overwrites file contents down to 0 KB, permanently destroying data even if a decryption key is later supplied or paid for. The group operates a tiered affiliate program (80/20 RaaS split, 60/40 data-extortion split, 50/50 access-monetization split), has listed roughly 94 victims as of July 20, 2026, primarily in the US, Australia, Canada, Western Europe, and Latin America, concentrated in healthcare, business services, manufacturing, hospitality, and construction, while explicitly excluding CIS countries, government, education, and non-profits. Attribution assessments point to Russian-speaking, CIS-timezone-aligned operators using aliases including 'superSonic' (RAMP forum) and 'Anubis__media' (XSS forum).

The malware's typical attack chain begins with spear-phishing (malicious attachments/links), exposed RDP, pre-existing malware loaders, or trojanized software updates for initial access. Post-compromise, the encryptor performs stealthy privilege checks by attempting to open a raw disk device handle (\\.\PHYSICALDRIVE0) rather than calling noisy Windows APIs like IsUserAnAdmin(), supports token manipulation/re-execution via an '/elevated' flag, conducts filesystem discovery excluding system and developer-tool directories (Windows, System32, Program Files, ProgramData, AppData, .nuget, .gradle, .vscode, efi, boot), and — where lateral movement has been observed — stages and exfiltrates data prior to encryption. Before encrypting, the payload terminates over 90 processes/services spanning SQL Server, backup software (Veeam, Acronis, BackupExec), and endpoint security products (Sophos, Symantec, Windows Defender components), then deletes Volume Shadow Copies via `vssadmin delete shadows /for=norealvolume /all /quiet`. Encrypted files receive the `.anubis` extension, a `RESTORE FILES.html` ransom note is dropped into affected directories, and the desktop wallpaper is changed via a registry modification referencing dropped icon/wallpaper assets in C:\ProgramData. When the destructive `/WIPEMODE` parameter is invoked, targeted files are irreversibly reduced to 0 KB in place of (or in addition to) encryption, removing any possibility of recovery regardless of ransom payment — a capability directly relevant to the Fairlife incident given the group's claim of full Nutanix-system encryption and its history of using the wipe capability to increase extortion leverage.

MITRE ATT&CK techniques used in TL-2026-1615

Credential Access

T1003 OS Credential Dumping

Collection

T1005 Data from Local System; T1074 Data Staged

Exfiltration

T1020 Automated Exfiltration; T1041 Exfiltration Over C2 Channel

Lateral Movement

T1021.001 Remote Desktop Protocol

Execution

T1059 Command and Scripting Interpreter; T1059.003 Windows Command Shell

Discovery

T1069 Permission Groups Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery

Persistence

T1078 Valid Accounts

defense-impairment

T1112 Modify Registry; T1685 Disable or Modify Tools; T1685.005 Clear Windows Event Logs

Initial Access

T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1566.001 Spearphishing Attachment

Privilege Escalation

T1134.001 Token Impersonation/Theft; T1548 Abuse Elevation Control Mechanism

Impact

T1485 Data Destruction; T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1491.001 Internal Defacement

Affected products and versions in Anubis Ransomware Encrypts Nutanix Systems and Exfiltrates

  • fairlife, LLC (The Coca-Cola Company) — Fairlife US production and corporate IT systems (Nutanix hyperconverged infrastructure)
    Vulnerable versions: all Fairlife US production-linked Nutanix/IT systems as of July 2026
  • Generic — Windows Server / Workstation environments (Anubis Windows encryptor)
    Vulnerable versions: all supported Windows versions lacking EDR/segmentation controls
  • Generic — Linux, NAS, VMware ESXi hosts (Anubis cross-platform encryptor variants)
    Vulnerable versions: unpatched/unsegmented Linux, NAS, and ESXi hosts

Remediation for Anubis Ransomware Encrypts Nutanix Systems and Exfiltrates

Immediate actions

  • Isolate and forensically image affected Nutanix/hyperconverged infrastructure before any recovery attempt
  • Rotate all credentials and API keys reachable from compromised segments; assume domain-wide credential exposure
  • Hunt for /KEY, /WIPEMODE, /elevated, /PATH, /PFAD command-line parameters in process-creation logs across the environment
  • Verify integrity and isolation (air-gap/immutability) of all backup repositories before any restore is attempted
  • Check for vssadmin delete shadows /for=norealvolume /all /quiet execution and shadow-copy status on all Windows hosts
  • Notify law enforcement (FBI/CISA in the US) and relevant data-protection regulators given claimed data exfiltration

Workarounds

  • Block execution of unsigned Go binaries from user-writable and temp directories
  • Restrict raw disk device access (\\.\PHYSICALDRIVE*) to trusted system processes via EDR policy

Longer-term hardening

  • Deploy EDR with behavioral detection tuned to mass file-rename and 0KB file-truncation patterns (wiper indicators)
  • Enforce MFA on all remote access (RDP, VPN, hypervisor/Nutanix Prism management) and disable direct internet-facing RDP
  • Maintain immutable, offline/air-gapped backups given Anubis's wipe-mode defeats decryption-based recovery entirely
  • Implement network segmentation between IT/OT/production systems to limit ransomware-driven production disruption
  • Deploy application allow-listing and script-execution controls to reduce Go-binary and living-off-the-land execution
  • Establish 24/7 monitoring for service/process termination bursts targeting backup and security agents

Timeline of Anubis Ransomware Encrypts Nutanix Systems and Exfiltrates

  • Anubis ransomware operation first observed publicly under the development codename 'Sphinx'
  • Group rebrands from Sphinx to Anubis, launching its formal RaaS/data-extortion/access-monetization affiliate program
  • Estimated initial compromise of fairlife systems, per Anubis's own leak-site claim of attacking 'a week ago' relative to its July 20-21 post
  • Coca-Cola discloses that a third party gained unauthorized access to fairlife systems related to production; US dairy production suspended, Canadian operations continue
  • Multiple outlets (BleepingComputer, Help Net Security, Engadget, ABC News, FoodNavigator) report Coca-Cola's confirmation and the US production halt
  • Anubis lists fairlife as a victim on its Tor data-leak site, claiming ~1TB of exfiltrated data and full encryption of Fairlife's Nutanix infrastructure
  • BleepingComputer and Cybernews report Anubis's direct quotes claiming the victim did not follow negotiation instructions and reported the incident instead
  • SecurityWeek coverage of the threat ingested and threat skeleton created by the TL-Intel-Harness HUNT phase
  • Anubis's leak-site listing sets an approximately one-week deadline from posting for ransom payment before the claimed 1TB dataset is published

Sources cited for Anubis Ransomware Encrypts Nutanix Systems and Exfiltrates

Threats related to Anubis Ransomware Encrypts Nutanix Systems and Exfiltrates

Detection coverage for TL-2026-1615

As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1615 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats