Malware News Anubis ransomware adds wiper to destroy files beyond recovery

Parkinsond

Level 19
Thread author
Dec 6, 2023
919
The Anubis ransomware-as-a-service (RaaS) operation has added to its file-encryptimg malware a wiper module that destroys targeted files, making recovery impossible even if the ransom is paid.

The researchers found the wiper in the latest Anubis samples they dissected, and believe the feature was introduced to increase the pressure on the victim to pay quicker instead of stalling negotiations or ignoring them altogether.

When activated, the wiper erases all file contents, reducing their sizes to 0 KB while keeping the filenames and structure intact.
The victim will still see all files in the expected directories, but their contents will be irreversibly destroyed, making recovery impossible.
Screenshot_15-6-2025_12456_www.bleepingcomputer.com.jpeg


The ransomware removes Volume Shadow Copies and terminates processes and services that could interfere with the encryption process.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top