# Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2 (CVE-2025-5777) Exploitation Wave

> The Anubis ransomware-as-a-service (RaaS) gang breached Fairlife LLC, Coca-Cola's dairy subsidiary, stole approximately 1TB of data, and temporarily disrupted U.S. production. Coca-Cola refused to pay and the attackers publicly leaked the stolen data after the ransom deadline expired on July 27, 2026. The intrusion lands inside a documented Anubis campaign wave that has hit roughly 91 organizations since early 2026 by exploiting the CitrixBleed 2 NetScaler vulnerability (CVE-2025-5777) and stolen VPN credentials for initial access, followed by RMM-tool abuse, credential dumping, and its signature wipe-capable encryptor.

- **Published:** 2026-07-27T00:00:00Z
- **Last reviewed:** 2026-08-13T23:42:34.958Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1729
- **ID:** TL-2026-1729
- **Severity:** CRITICAL (CVSS 7.5)
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Actor:** Anubis Ransomware Group (Russia)
- **Detections:** 9 · **IOCs:** 40 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-5777

## Description

Anubis is a Ransomware-as-a-Service (RaaS) operation first observed in November/December 2024, distinguished from typical double-extortion crews by a built-in destructive wiper mode alongside its ECIES (Elliptic Curve Integrated Encryption Scheme) file encryptor. In mid-July 2026 Coca-Cola disclosed that an unauthorized third party had accessed a portion of Fairlife's corporate systems and taken data, temporarily suspending U.S. production at Fairlife's four American facilities while existing inventory covered retail shortfalls; Canadian operations were unaffected. On July 20, 2026 the Anubis group listed Coca-Cola/Fairlife on its dark-web data-leak site, claiming roughly 1TB of stolen confidential data and setting a countdown-timer ransom deadline. Coca-Cola reported the intrusion to law enforcement and declined to negotiate; when the deadline lapsed on July 27, 2026, Anubis published the stolen data and Coca-Cola publicly confirmed the theft, stating retail availability of Fairlife products was largely unimpacted and that quality/safety were not affected. Reporting on the systems impacted has varied between outlets, with one report describing encrypted Nutanix hyper-converged infrastructure and another citing a Coca-Cola characterization of 'archived systems rather than active operational environments' -- both are reproduced here as sourced, unreconciled claims from different outlets.

This incident sits inside a broader, actively-tracked Anubis campaign. Since early 2026, Arctic Wolf has investigated multiple Anubis intrusions that combine two initial-access paths: (1) valid, stolen VPN/Cisco AnyConnect credentials originating from bulletproof/VPS hosting ASNs, and (2) exploitation of CVE-2025-5777 ('CitrixBleed 2'), a pre-authentication memory-disclosure vulnerability in Citrix NetScaler ADC/Gateway that leaks session tokens and enables MFA bypass; CISA added CVE-2025-5777 to its Known Exploited Vulnerabilities catalog on July 10, 2025. Separate reporting indicates the same CitrixBleed-2-driven Anubis wave has been linked to roughly 91 victim organizations as of early July 2026. Following initial access, Anubis affiliates pivot via RDP/SMB into domain controllers, hypervisors, backup infrastructure, and NAS devices; deploy legitimate RMM tools (ScreenConnect, Zoho Assist, MeshAgent, UltraVNC, mRemoteNG, Remotely Desktop, Total Software Deployment) for persistence; use PsExec for lateral tool transfer; dump credentials with Mimikatz and NTDS.dit copies; tunnel and exfiltrate data via Cloudflared, SSH SOCKS proxies, S3 Browser, rclone, and s5cmd; disable AV/EDR (including Windows Defender and Sophos) and clear event logs; and finally detonate the ECIES-based encryptor, appending the '.anubis' extension and dropping an HTML ransom note ('RESTORE FILES.html'). A companion '/WIPEMODE' command-line switch overwrites file contents to 0 KB while preserving filenames, rendering recovery impossible even with an intact directory structure -- a punitive option affiliates can trigger after failed negotiations. Anubis operates a tiered affiliate/monetization model (80% share for ransomware affiliates, 60% for data-extortion-only affiliates, 50% for initial access brokers) and has listed close to 100 victims across healthcare, construction, hospitality/gaming, and now food-and-beverage manufacturing, concentrated in the U.S., Canada, Australia, Peru, and France. Operational indicators (Russian-language forum posts and ransom-note strings, Moscow-Standard-Time negotiation hours, and an explicit prohibition on targeting former Soviet-bloc states) point to Russia/CIS-based operators, and some reporting suggests Anubis may be a rebrand of, or closely linked to, an earlier 'Sphinx' ransomware operation -- both attribution threads are sourced but not independently confirmed.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1133 External Remote Services
- T1566.001 Spearphishing Attachment
- T1078 Valid Accounts
- T1059 Command and Scripting Interpreter
- T1569.002 Service Execution
- T1053.005 Scheduled Task
- T1219 Remote Access Tools
- T1134 Access Token Manipulation
- T1134.002 Create Process with Token
- T1548 Abuse Elevation Control Mechanism
- T1685 Disable or Modify Tools
- T1685.005 Clear Windows Event Logs
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1003.001 LSASS Memory
- T1003.003 NTDS
- T1555.003 Credentials from Web Browsers
- T1083 File and Directory Discovery
- T1018 Remote System Discovery
- T1021.001 Remote Desktop Protocol
- T1021.002 SMB/Windows Admin Shares
- T1570 Lateral Tool Transfer
- T1560 Archive Collected Data
- T1005 Data from Local System
- T1572 Protocol Tunneling
- T1090 Proxy
- T1105 Ingress Tool Transfer
- T1567.002 Exfiltration to Cloud Storage
- T1048 Exfiltration Over Alternative Protocol
- T1486 Data Encrypted for Impact
- T1490 Inhibit System Recovery
- T1489 Service Stop
- T1561.001 Disk Content Wipe
- T1657 Financial Theft
- T1539 Steal Web Session Cookie
- T1087.002 Account Discovery: Domain Account
- T1112 Modify Registry
- T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- T1485 Data Destruction

## Sources

- [Coca-Cola confirms data theft in Fairlife ransomware attack](https://www.bleepingcomputer.com/news/security/coca-cola-confirms-data-theft-in-fairlife-ransomware-attack/)
- [Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak](https://www.bleepingcomputer.com/news/security/anubis-ransomware-claims-coca-cola-fairlife-attack-threatens-data-leak/)
- [Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack](https://www.securityweek.com/coca-cola-confirms-data-breach-after-fairlife-ransomware-attack/)
- [Ransomware Group Threatening to Leak Data Stolen From Coca-Cola's Fairlife](https://www.securityweek.com/ransomware-group-threatening-to-leak-data-stolen-from-coca-colas-fairlife/)
- [Anubis ransomware claims Coca-Cola's Fairlife data breach](https://cybernews.com/security/coca-cola-fairlife-ransomware-attack/)
- [Threat group claims credit for ransomware attack on Coca-Cola's dairy unit](https://www.cybersecuritydive.com/news/threat-group-ransomware-coca-colas-dairy-Fairlife/825900/)
- [Anubis Ransomware targets Coca-Cola Fairlife Dairy Business, claims 1TB Data Leak](https://www.cybersecurity-insiders.com/anubis-ransomware-targets-coca-cola-fairlife-dairy-business-claims-1tb-data-leak/)
- [Anubis ransomware adds wiper to destroy files beyond recovery](https://www.bleepingcomputer.com/news/security/anubis-ransomware-adds-wiper-to-destroy-files-beyond-recovery/)
- [Wipe, leak, extort: The crazy hybrid playbook of Anubis ransomware](https://blog.barracuda.com/2025/07/11/wipe--leak--extort--the-crazy-hybrid-playbook-of-anubis-ransomwa)
- [Anubis Ransomware Targets Global Victims with Wiper Functionality](https://www.picussecurity.com/resource/blog/anubis-ransomware-targets-global-victims-with-wiper-functionality)
- [Anubis Ransomware: Operational Profile, Attack Chain, and Response Priorities](https://www.provendata.com/blog/anubis-ransomware)
- [Anubis: A Deep Dive into the Emerging Ransomware](https://www.bitsight.com/blog/anubis-ransomware-group-overview-and-evolution)
- [From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks](https://arcticwolf.com/resources/blog/citrixbleed-2-to-cloudflared-the-tools-and-techniques-behind-anubis-ransomware-attacks/)
- [Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials](https://thehackernews.com/2026/07/ransomware-groups-turn-to-citrix-bleed.html)
- [NVD - CVE-2025-5777 Detail](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-5777)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1729
