Anubis
Ransomware-as-a-Service (RaaS) operation · Financial — ransomware and regulatory-pressure extortion
Tactics, Techniques & Procedures (TTPs)
- Novel regulatory notification extortion: explicitly threatens to notify HIPAA OCR (US), ICO (UK), and national DPAs (EU) if ransom is not paid
- Data-theft-only affiliate tier: exfiltration without encryption, relying solely on regulatory notification threat (60% affiliate / 40% core)
- Go-based encryptor with AES-256-CTR per-file encryption and RSA-4096 key encapsulation
- Initial access via phishing, VPN appliance exploitation (Cisco ASA, Fortinet, Ivanti), and RMM tool compromise
- Post-intrusion: ADFind, BloodHound, LSASS dumping, DCSync, Rclone exfiltration to Mega.nz
- EDR tampering via driver-based killers; domain-wide encryption via PsExec or Group Policy
- Tor-based leak site with multi-stage victim listing (contacted → deadline → published)
Known Targets
Analyst Notes
Anubis emerged November 2024 with 35+ claimed victims as of mid-2026. The regulatory notification extortion tactic is the group's defining innovation: threatening to report breaches to HIPAA OCR, ICO, or national DPAs transforms a bilateral extortion negotiation into a three-party problem where the regulator becomes an involuntary amplifier of pressure. The data-theft-only affiliate tier demonstrates that the group treats the regulatory threat as independently valuable against healthcare organisations with resilient backup infrastructure. Standard ransomware IR is insufficient: legal counsel with regulatory expertise must assess notification obligations independently of payment decisions.