ZeroHour

anubis

ransomware group · aka Anubis, Anubis ransomware (Phobos/Dharma-linked per some researchers) · unknown; researchers have noted code and artifact similarities to the long-running Phobos/Dharma (CrySiS) ransomware family, but no confirmed operator background or country · active since Late 2024 (per vendor research; exact date varies by source). Leak-site coverage on this dashboard begins 2026-09-09.

Victims · 7d
2▲1 vs prev. week
Victims · 30d
6active targets
Victims · 90d
28
All-time (tracked)
110since 2025-02-25
Last post
09-15 02:30UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Anubis is a Windows ransomware and data-extortion operation first documented by researchers in late 2024, with several vendors noting similarities to the Phobos/Dharma (CrySiS) family, though formal attribution remains unknown. The group practices double extortion, encrypting files and publishing victim names on a Tor-based leak blog when negotiations or payments do not occur. Publicly reported victim volume and ransom activity have been modest compared with major ransomware-as-a-service brands, and no law-enforcement action or takedown has been announced. This dashboard's leak-site feed shows low-volume activity, with a single listing (Gellibrand Support Services) since tracking began on 2026-09-09. This group is distinct from the unrelated 'Anubis' Android banking trojan that shares the name.

Tactics & tooling
  • Windows file encryptor that appends an extension to encrypted files and drops ransom notes (per vendor write-ups)
  • Code and artifact similarities to Phobos/Dharma (CrySiS) ransomware noted by researchers
  • Initial access typically linked to exposed RDP or remote-access services; no specific CVE publicly attributed (unknown)
  • Double extortion: data exfiltration before encryption, followed by leak-site listing on non-payment
  • Victim shaming via Tor-based leak blog; historically low posting volume
  • Broad sector targeting with no clear industry concentration in public reporting (unknown)
  • Cryptocurrency ransom demands; demand amounts not publicly disclosed (unknown)
Targeted sectors
Nonprofit / social servicesVarious (limited public data; no confirmed concentration)
Notable public victims

Gellibrand Support Services - Australian community/disability support not-for-profit (listed on leak site 2026-09-09)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Advanced HPC · Aug 14, 2025Leakage of internal documents at a company engaged in the development and implementation of HPC systems for science and defence.
Disneyland Paris · Jun 20, 2025Confidential Disneyland documents.
Parkway Construction LLC · Jun 11, 2025Blueprints of L3Harris, General Atomics and Virgin Galactic.
Two Kings Casino Resort · Apr 23, 2025Leaked ultra-detailed blueprints of a casino that plans a grand opening in 2026.
DG2 Design · Apr 1, 2025Blueprints of M1 Bank, Mastercard and so on.
Ambleside · Mar 20, 2025Breach of personal data of patients, company employees, and dozens of incidents, including Patient abuse.
Pound Road Medical Centre · Feb 25, 2025
Summit Home Health, INC. · Feb 25, 2025
Comercializadora S&E Perú · Feb 25, 2025
First Defense Fire Protection · Feb 25, 2025

In the newsAll →

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .