Anubis Ransomware Encrypts and Wipes Files, Making Recovery Impossible Even After Payment
Jun 16, 2025
Malware / Ransomware
 An emerging ransomware strain has been discovered incorporating capabilities to encrypt files as well as permanently erase them, a development that has been described as a "rare dual-threat."  "The ransomware features a 'wipe mode,' which permanently erases files, rendering recovery impossible even if the ransom is paid," Trend Micro researchers Maristel Policarpio, Sarah Pearl Camiling, and Sophia Nilette Robles said  in a report published last week.  The ransomware-as-a-service (RaaS) operation in question is named Anubis, which became active  in December 2024, claiming victims across healthcare, hospitality, and construction sectors  in Australia, Canada, Peru, and the U.S. Analysis of early, trial samples of the ransomware suggests that the developers initially named it Sphinx, before tweaking the brand name in the final version.   It's worth noting that the e-crime crew has no ties to an Android banking trojan  and a Python-based backdoor  of the s...