Anubis Ransomware: Data Encryption & Destruction Alert
- A newly discovered Anubis ransomware strain is upping the stakes for victims by offering cybercriminals a "wipe mode" that permanently destroys data after encryption.
- The Anubis operation combines traditional file encryption with file destruction routines.
- First identified in December 2024, Anubis shares similarities with a work-in-progress sample called Sphinx, according to Trend Micro.
Be informed: A new Anubis ransomware strain now includes a data wiping feature, permanently destroying files after encryption, making data recovery unfeasible.This Ransomware-as-a-Service (RaaS) is designed to pressure victims into swift payments. News Directory 3 presents a concise overview of this rising cyber threat, including key points from the attack. Discover the latest defenses and stay protected. What’s next for Anubis?
{ "@context": "https://schema.org", "@type": "NewsArticle", "mainEntityOfPage": { "@type": "WebPage", "@id": "https://www.newsdirectory3.com/anubis-ransomware-destroys-data-after-encryption/" }, "headline": "Anubis Ransomware: New Strain Destroys Data After Encryption", "description": "A new Anubis ransomware strain offers a data wiping option, permanently destroying files after encryption. Learn how this Ransomware-as-a-Service operates.", "image": [ "https://www.techspot.com/images2/news/bigimage/2025/06/2025-06-16-image-16.jpg" ], "datePublished": "2025-06-16T19:33:02+00:00", "dateModified": "2025-06-16T19:33:02+00:00", "author": { "@type": "Association", "name": "newsdirectory3.com" }, "publisher": { "@type": "Organization", "name": "newsdirectory3.com", "logo": { "@type": "ImageObject", "url": "data:image/svg+xml," } } }
Anubis Ransomware Adds data Wiping to Encryption Attacks
Updated June 16, 2025
A newly discovered Anubis ransomware strain is upping the stakes for victims by offering cybercriminals a “wipe mode” that permanently destroys data after encryption. This ransomware-as-a-Service (RaaS) campaign, while still relatively new, poses a significant threat due to its potential for irreversible data loss.
The Anubis operation combines traditional file encryption with file destruction routines. Once activated, the wipe mode makes data recovery unfeasible, even if the ransom is paid. security experts believe this tactic is designed to pressure victims into quicker payments, eliminating negotiation or the option to ignore the threat.

First identified in December 2024, Anubis shares similarities with a work-in-progress sample called Sphinx, according to Trend Micro. The primary difference lies in the ransom notes displayed on infected systems. Currently, Anubis’ dark web extortion page lists onyl eight victims, suggesting the operation is still in its early stages of progress and expansion.
