Threat reportRansomwareTL-2026-1729

Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2 (CVE-2025-5777) Exploitation Wave

criticalACTIVE

Anubis Ransomware Group Confirms Data Theft in Coca-Cola (TL-2026-1729), also tracked as Fairlife Ransomware Attack, is a critical-severity ransomware operation scored CVSS 7.5, first published 2026-07-27 and last reviewed 2026-08-13. It is attributed to Anubis Ransomware Group (Russia) with medium confidence, affects Fairlife LLC / The Coca-Cola Company Corporate IT infrastructure, references 1 CVE (CVE-2025-5777), maps to 40 MITRE ATT&CK techniques (T1003.001, T1003.003, T1005), and is covered by 9 detection rules and 40 indicators of compromise.

CVSS
7.5/10Critical
CVEs
1Referenced vulnerabilities
Techniques
40MITRE ATT&CK
Actors
1Anubis Ransomware Group
Detection rules
9SPL · KQL · Sigma
IOCs
40Indicators of compromise

Key facts for TL-2026-1729

Threat ID
TL-2026-1729
Also known as
Fairlife Ransomware Attack, Coca-Cola Fairlife Data Breach
Severity
CRITICAL
CVSS
7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Status
ACTIVE
Category
RANSOMWARE
First published
Last reviewed
Attribution
Anubis Ransomware Group
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
food and beverage, manufacturing, health, construction, hospitality, gaming
Target regions
North America, united states of america, canada, australia, peru, france
Detection rules
9
Indicators of compromise
40
Updates
2026-08-13 · revalidated 1× · latest source

Malware and tooling in Anubis Ransomware Group Confirms Data Theft in Coca-Cola

Malware and tooling: anubis, Cloudflared, Mimikatz, PCHunter, Rclone - S1040

How Anubis Ransomware Group Confirms Data Theft in Coca-Cola works

The Anubis ransomware-as-a-service (RaaS) gang breached Fairlife LLC, Coca-Cola's dairy subsidiary, stole approximately 1TB of data, and temporarily disrupted U.S. production. Coca-Cola refused to pay and the attackers publicly leaked the stolen data after the ransom deadline expired on July 27, 2026. The intrusion lands inside a documented Anubis campaign wave that has hit roughly 91 organizations since early 2026 by exploiting the CitrixBleed 2 NetScaler vulnerability (CVE-2025-5777) and stolen VPN credentials for initial access, followed by RMM-tool abuse, credential dumping, and its signature wipe-capable encryptor.

Anubis is a Ransomware-as-a-Service (RaaS) operation first observed in November/December 2024, distinguished from typical double-extortion crews by a built-in destructive wiper mode alongside its ECIES (Elliptic Curve Integrated Encryption Scheme) file encryptor. In mid-July 2026 Coca-Cola disclosed that an unauthorized third party had accessed a portion of Fairlife's corporate systems and taken data, temporarily suspending U.S. production at Fairlife's four American facilities while existing inventory covered retail shortfalls; Canadian operations were unaffected. On July 20, 2026 the Anubis group listed Coca-Cola/Fairlife on its dark-web data-leak site, claiming roughly 1TB of stolen confidential data and setting a countdown-timer ransom deadline. Coca-Cola reported the intrusion to law enforcement and declined to negotiate; when the deadline lapsed on July 27, 2026, Anubis published the stolen data and Coca-Cola publicly confirmed the theft, stating retail availability of Fairlife products was largely unimpacted and that quality/safety were not affected. Reporting on the systems impacted has varied between outlets, with one report describing encrypted Nutanix hyper-converged infrastructure and another citing a Coca-Cola characterization of 'archived systems rather than active operational environments' -- both are reproduced here as sourced, unreconciled claims from different outlets.

This incident sits inside a broader, actively-tracked Anubis campaign. Since early 2026, Arctic Wolf has investigated multiple Anubis intrusions that combine two initial-access paths: (1) valid, stolen VPN/Cisco AnyConnect credentials originating from bulletproof/VPS hosting ASNs, and (2) exploitation of CVE-2025-5777 ('CitrixBleed 2'), a pre-authentication memory-disclosure vulnerability in Citrix NetScaler ADC/Gateway that leaks session tokens and enables MFA bypass; CISA added CVE-2025-5777 to its Known Exploited Vulnerabilities catalog on July 10, 2025. Separate reporting indicates the same CitrixBleed-2-driven Anubis wave has been linked to roughly 91 victim organizations as of early July 2026. Following initial access, Anubis affiliates pivot via RDP/SMB into domain controllers, hypervisors, backup infrastructure, and NAS devices; deploy legitimate RMM tools (ScreenConnect, Zoho Assist, MeshAgent, UltraVNC, mRemoteNG, Remotely Desktop, Total Software Deployment) for persistence; use PsExec for lateral tool transfer; dump credentials with Mimikatz and NTDS.dit copies; tunnel and exfiltrate data via Cloudflared, SSH SOCKS proxies, S3 Browser, rclone, and s5cmd; disable AV/EDR (including Windows Defender and Sophos) and clear event logs; and finally detonate the ECIES-based encryptor, appending the '.anubis' extension and dropping an HTML ransom note ('RESTORE FILES.html'). A companion '/WIPEMODE' command-line switch overwrites file contents to 0 KB while preserving filenames, rendering recovery impossible even with an intact directory structure -- a punitive option affiliates can trigger after failed negotiations. Anubis operates a tiered affiliate/monetization model (80% share for ransomware affiliates, 60% for data-extortion-only affiliates, 50% for initial access brokers) and has listed close to 100 victims across healthcare, construction, hospitality/gaming, and now food-and-beverage manufacturing, concentrated in the U.S., Canada, Australia, Peru, and France. Operational indicators (Russian-language forum posts and ransom-note strings, Moscow-Standard-Time negotiation hours, and an explicit prohibition on targeting former Soviet-bloc states) point to Russia/CIS-based operators, and some reporting suggests Anubis may be a rebrand of, or closely linked to, an earlier 'Sphinx' ransomware operation -- both attribution threads are sourced but not independently confirmed.

MITRE ATT&CK techniques used in TL-2026-1729

Credential Access

T1003.001 LSASS Memory; T1003.003 NTDS; T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers

Collection

T1005 Data from Local System; T1560 Archive Collected Data

Discovery

T1018 Remote System Discovery; T1083 File and Directory Discovery; T1087.002 Account Discovery: Domain Account

Lateral Movement

T1021.001 Remote Desktop Protocol; T1021.002 SMB/Windows Admin Shares; T1570 Lateral Tool Transfer

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1112 Modify Registry

Exfiltration

T1048 Exfiltration Over Alternative Protocol; T1567.002 Exfiltration to Cloud Storage

Persistence

T1053.005 Scheduled Task; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Execution

T1059 Command and Scripting Interpreter; T1569.002 Service Execution

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1566.001 Spearphishing Attachment

Command and Control

T1090 Proxy; T1105 Ingress Tool Transfer; T1572 Protocol Tunneling

Privilege Escalation

T1134 Access Token Manipulation; T1134.002 Create Process with Token; T1548 Abuse Elevation Control Mechanism

command-and-control

T1219 Remote Access Tools

Impact

T1485 Data Destruction; T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1561.001 Disk Content Wipe; T1657 Financial Theft

defense-impairment

T1685 Disable or Modify Tools; T1685.005 Clear Windows Event Logs

Affected products and versions in Anubis Ransomware Group Confirms Data Theft in Coca-Cola

  • Fairlife LLC / The Coca-Cola Company — Corporate IT infrastructure (reported: Nutanix hyper-converged virtualization; also reported: archived systems)
    Vulnerable versions: N/A - enterprise network compromise
  • Cloud Software Group (Citrix) — NetScaler ADC and NetScaler Gateway
    Vulnerable versions: 13.1 before 13.1-58.32; 14.1 before 14.1-43.56; 12.1-FIPS before 12.1-55.328-FIPS; 13.1-FIPS and NDcPP before 13.1-37.235-FIPS and NDcPP; 12.1 (EOL); 13.0 (EOL)
    Fixed in: 13.1-58.32; 14.1-43.56; 12.1-55.328-FIPS; 13.1-37.235-FIPS and NDcPP

Remediation for Anubis Ransomware Group Confirms Data Theft in Coca-Cola

Patches

  • Citrix NetScaler ADC/Gateway security update for CVE-2025-5777 (builds 13.1-58.32, 14.1-43.56, 12.1-55.328-FIPS, 13.1-37.235-FIPS and NDcPP)

Immediate actions

  • Patch NetScaler ADC/Gateway to fixed builds (13.1-58.32+, 14.1-43.56+, 12.1-55.328-FIPS+, 13.1-37.235-FIPS and NDcPP+) to close CVE-2025-5777
  • Terminate all active ICA/PCoIP/AAA sessions immediately after patching to invalidate any session tokens already leaked via memory overread
  • Force VPN/Cisco AnyConnect credential resets and MFA re-enrollment for all Gateway and AAA virtual server users
  • Hunt for and remove unauthorized RMM/remote-access tools (ScreenConnect, Zoho Assist, MeshAgent, UltraVNC, mRemoteNG, Remotely Desktop, Total Software Deployment) not sanctioned by IT
  • Isolate and preserve forensic artifacts on affected NAS, backup, hypervisor, and domain controller hosts before reconnecting backup infrastructure

Workarounds

  • If patching is delayed, restrict management-plane and Gateway/AAA vServer access to trusted source IPs only and enable enhanced session monitoring

Longer-term hardening

  • Deploy EDR/SIEM detections for mass file rename to the .anubis extension, vssadmin shadow-copy deletion, and coordinated backup/AV service termination
  • Implement immutable, offline/air-gapped backups with regular restoration testing to survive wiper-mode (/WIPEMODE) attacks
  • Network-segment backup infrastructure, domain controllers, and hypervisors away from general user VLANs and internet-facing gateways
  • Deploy application allowlisting to block unauthorized tunneling/exfiltration binaries (Cloudflared, rclone, s5cmd, S3 Browser) on servers
  • Establish credential-dumping detections for LSASS access (Mimikatz) and NTDS.dit extraction/archiving

CVEs associated with Anubis Ransomware Group Confirms Data Theft in Coca-Cola

CVE-2025-5777

Weaknesses (CWE) in Anubis Ransomware Group Confirms Data Theft in Coca-Cola

CWE-908, CWE-125, CWE-457

Timeline of Anubis Ransomware Group Confirms Data Theft in Coca-Cola

  • Anubis RaaS operation first identified; first known victim is a healthcare provider in Victoria, Australia.
  • Second known Anubis victim, a Canadian healthcare organization, is compromised as the group's dark-web leak site becomes active.
  • Citrix discloses CVE-2025-5777 ('CitrixBleed 2'), a pre-authentication memory-disclosure vulnerability in NetScaler ADC/Gateway enabling session-token theft and MFA bypass.
  • CISA adds CVE-2025-5777 to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild.
  • Security researchers (Barracuda, BleepingComputer, Picus) report Anubis has added a destructive '/WIPEMODE' file-wiping capability to its ransomware payload.
  • Arctic Wolf begins observing a wave of Anubis intrusions combining CVE-2025-5777 exploitation and stolen VPN credentials with abuse of legitimate RMM tools for persistence.
  • Anubis claims initial access to Fairlife's network occurred about a week before Coca-Cola's July 16 disclosure, per the group's own statement (not independently confirmed by Coca-Cola).
  • Unauthorized access to Fairlife's corporate network occurs (exact intrusion date undisclosed by Coca-Cola), preceding the July 16 public disclosure.
  • Coca-Cola discloses the cyberattack, confirming unauthorized third-party access to Fairlife systems and temporary suspension of U.S. production at Fairlife's facilities.
  • The Anubis ransomware group lists Coca-Cola/Fairlife on its dark-web data-leak site, claiming approximately 1TB of stolen confidential data and starting a ransom countdown timer.
  • Coca-Cola confirms data theft publicly and states most Fairlife U.S. production has resumed, with retail availability and product safety largely unaffected.
  • The ransom deadline expires; Anubis publicly releases the stolen Fairlife data after Coca-Cola declines to pay and reports the intrusion to law enforcement.
  • Eclypsium publishes analysis attributing the Fairlife breach to CitrixBleed 2 (CVE-2025-5777) and warning that patching NetScaler alone does not invalidate session tokens/credentials already harvested from the appliance pre-patch.

Update history for TL-2026-1729

Sources cited for Anubis Ransomware Group Confirms Data Theft in Coca-Cola

Detection coverage for TL-2026-1729

As of 2026-08-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1729 across Splunk SPL, Microsoft KQL and Sigma, covering 40 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
40 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats