Skip to content
← All Threat Actors
Cybercrime critical Eastern Europe (assessed)

Anubis

Ransomware-as-a-Service (RaaS) operation · Financial — ransomware and regulatory-pressure extortion

Reports 1
Active Since 2024
Last Reported 1 Jul 2026
Sectors Targeted healthcare, government, finance, critical-infrastructure

Tactics, Techniques & Procedures (TTPs)

  • Novel regulatory notification extortion: explicitly threatens to notify HIPAA OCR (US), ICO (UK), and national DPAs (EU) if ransom is not paid
  • Data-theft-only affiliate tier: exfiltration without encryption, relying solely on regulatory notification threat (60% affiliate / 40% core)
  • Go-based encryptor with AES-256-CTR per-file encryption and RSA-4096 key encapsulation
  • Initial access via phishing, VPN appliance exploitation (Cisco ASA, Fortinet, Ivanti), and RMM tool compromise
  • Post-intrusion: ADFind, BloodHound, LSASS dumping, DCSync, Rclone exfiltration to Mega.nz
  • EDR tampering via driver-based killers; domain-wide encryption via PsExec or Group Policy
  • Tor-based leak site with multi-stage victim listing (contacted → deadline → published)

Known Targets

US healthcare organisations (17 confirmed as of July 2026)Financial servicesLocal governmentLegal sectorUK and EU organisations under GDPR/UK GDPR jurisdiction

Analyst Notes

Anubis emerged November 2024 with 35+ claimed victims as of mid-2026. The regulatory notification extortion tactic is the group's defining innovation: threatening to report breaches to HIPAA OCR, ICO, or national DPAs transforms a bilateral extortion negotiation into a three-party problem where the regulator becomes an involuntary amplifier of pressure. The data-theft-only affiliate tier demonstrates that the group treats the regulatory threat as independently valuable against healthcare organisations with resilient backup infrastructure. Standard ransomware IR is insufficient: legal counsel with regulatory expertise must assess notification obligations independently of payment decisions.