anubis
ransomware group · aka Anubis, Anubis ransomware (Phobos/Dharma-linked per some researchers) · unknown; researchers have noted code and artifact similarities to the long-running Phobos/Dharma (CrySiS) ransomware family, but no confirmed operator background or country · active since Late 2024 (per vendor research; exact date varies by source). Leak-site coverage on this dashboard begins 2026-09-09.
Anubis is a Windows ransomware and data-extortion operation first documented by researchers in late 2024, with several vendors noting similarities to the Phobos/Dharma (CrySiS) family, though formal attribution remains unknown. The group practices double extortion, encrypting files and publishing victim names on a Tor-based leak blog when negotiations or payments do not occur. Publicly reported victim volume and ransom activity have been modest compared with major ransomware-as-a-service brands, and no law-enforcement action or takedown has been announced. This dashboard's leak-site feed shows low-volume activity, with a single listing (Gellibrand Support Services) since tracking began on 2026-09-09. This group is distinct from the unrelated 'Anubis' Android banking trojan that shares the name.
- Windows file encryptor that appends an extension to encrypted files and drops ransom notes (per vendor write-ups)
- Code and artifact similarities to Phobos/Dharma (CrySiS) ransomware noted by researchers
- Initial access typically linked to exposed RDP or remote-access services; no specific CVE publicly attributed (unknown)
- Double extortion: data exfiltration before encryption, followed by leak-site listing on non-payment
- Victim shaming via Tor-based leak blog; historically low posting volume
- Broad sector targeting with no clear industry concentration in public reporting (unknown)
- Cryptocurrency ransom demands; demand amounts not publicly disclosed (unknown)
Gellibrand Support Services - Australian community/disability support not-for-profit (listed on leak site 2026-09-09)
No public figure.
Leak-site victims110 posts · newest first
| Victim | Discovered | Details |
|---|---|---|
| Advanced HPC | · Aug 14, 2025 | Leakage of internal documents at a company engaged in the development and implementation of HPC systems for science and defence. |
| Disneyland Paris | · Jun 20, 2025 | Confidential Disneyland documents. |
| Parkway Construction LLC | · Jun 11, 2025 | Blueprints of L3Harris, General Atomics and Virgin Galactic. |
| Two Kings Casino Resort | · Apr 23, 2025 | Leaked ultra-detailed blueprints of a casino that plans a grand opening in 2026. |
| DG2 Design | · Apr 1, 2025 | Blueprints of M1 Bank, Mastercard and so on. |
| Ambleside | · Mar 20, 2025 | Breach of personal data of patients, company employees, and dozens of incidents, including Patient abuse. |
| Pound Road Medical Centre | · Feb 25, 2025 | — |
| Summit Home Health, INC. | · Feb 25, 2025 | — |
| Comercializadora S&E Perú | · Feb 25, 2025 | — |
| First Defense Fire Protection | · Feb 25, 2025 | — |