Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2 (CVE-2025-5777) Exploitation Wave — Threadlinqs Intelligence
As of 2026-08-13, Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2 (CVE-2025-5777) Exploitation Wave is a critical-severity ransomware threat attributed to Anubis Ransomware Group (Russia (suspected, unconfirmed)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 40 indicators of compromise.
Threat ID: TL-2026-1729 · Severity: CRITICAL · CVSS: 7.5 · Status: ACTIVE · Category: RANSOMWARE
Updated: 2026-08-13 · revalidated 1× · latest source
Attribution: Anubis Ransomware Group · Russia (suspected, unconfirmed) · FINANCIAL
The Anubis ransomware-as-a-service (RaaS) gang breached Fairlife LLC, Coca-Cola's dairy subsidiary, stole approximately 1TB of data, and temporarily disrupted U.S. production. Coca-Cola refused to pay
Anubis is a Ransomware-as-a-Service (RaaS) operation first observed in November/December 2024, distinguished from typical double-extortion crews by a built-in destructive wiper mode alongside its ECIES (Elliptic Curve Integrated Encryption Scheme) file encryptor. In mid-July 2026 Coca-Cola disclosed that an unauthorized third party had accessed a portion of Fairlife's corporate systems and taken data, temporarily suspending U.S. production at Fairlife's four American facilities while existing inventory covered retail shortfalls; Canadian operations were unaffected. On July 20, 2026 the Anubis group listed Coca-Cola/Fairlife on its dark-web data-leak site, claiming roughly 1TB of stolen confidential data and setting a countdown-timer ransom deadline. Coca-Cola reported the intrusion to law enforcement and declined to negotiate; when the deadline lapsed on July 27, 2026, Anubis published the stolen data and Coca-Cola publicly confirmed the theft, stating retail availability of Fairlife products was largely unimpacted and that quality/safety were not affected. Reporting on the systems impacted has varied between outlets, with one report describing encrypted Nutanix hyper-converged infrastructure and another citing a Coca-Cola characterization of 'archived systems rather than active operational environments' -- both are reproduced here as sourced, unreconciled claims from different outlets.
This incident sits inside a broader, actively-tracked Anubis campaign. Since early 2026, Arctic Wolf has investigated multiple Anubis intrusions that combine two initial-access paths: (1) valid, stolen VPN/Cisco AnyConnect credentials originating from bulletproof/VPS hosting ASNs, and (2) exploitation of CVE-2025-5777 ('CitrixBleed 2'), a pre-authentication memory-disclosure vulnerability in Citrix NetScaler ADC/Gateway that leaks session tokens and enables MFA bypass; CISA added CVE-2025-5777 to its Known Exploited Vulnerabilities catalog on July 10, 2025. Separate reporting indicates the same CitrixBleed-2-driven Anubis wave has been linked to roughly 91 victim organizations as of early July 2026. Following initial access, Anubis affiliates pivot via RDP/SMB into domain controllers, hypervisors, backup infrastructure, and NAS devices; deploy legitimate RMM tools (ScreenConnect, Zoho Assist, MeshAgent, UltraVNC, mRemoteNG, Remotely Desktop, Total Software Deployment) for persistence; use PsExec for lateral tool transfer; dump credentials with Mimikatz and NTDS.dit copies; tunnel and exfiltrate data via Cloudflared, SSH SOCKS proxies, S3 Browser, rclone, and s5cmd; disable AV/EDR (including Windows Defender and Sophos) and clear event logs; and finally detonate the ECIES-based encryptor, appending the '.anubis' extension and dropping an HTML ransom note ('RESTORE FILES.html'). A companion '/WIPEMODE' command-line switch overwrites file contents to 0 KB while preserving filenames, rendering recovery impossible even with an intact directory structure -- a punitive option affiliates can trigger after failed negotiations. Anubis operates a tiered affiliate/monetization model (80% share for ransomware affiliates, 60% for data-extortion-only affiliates, 50% for initial access brokers) and has listed close to 100 victims across healthcare, construction, hospitality/gaming, and now food-and-beverage manufacturing, concentrated in the U.S., Canada, Australia, Peru, and France. Operational indicators (Russian-language forum posts and ransom-note strings, Moscow-Standard-Time negotiation hours, and an explicit prohibition on targeting former Soviet-bloc states) point to Russia/CIS-based operators, and some reporting suggests Anubis may be a rebrand of, or closely linked to, an earlier 'Sphinx' ransomware operation -- both attribution threads are sourced but not independently confirmed.
Weaknesses (CWE)
CWE-908, CWE-125, CWE-457
Target sectors: food and beverage, manufacturing, health, construction, hospitality, gaming
Target regions: North America, united states of america, canada, australia, peru, france
Detections & IOCs
As of 2026-08-24, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 40 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, CRITICAL, threat intelligence, cybersecurity, CVE-2025-5777, T1190, T1133, T1566.001, T1078, T1059, T1569.002, T1053.005, T1219, T1134, T1134.002