What Anubis Ransomware Is and How the Affiliate Model Works

Anubis is a ransomware-as-a-service (RaaS) operation that has been active since December 2024, when it first surfaced under the test name "Sphinx" before rebranding to its current identity. Like other RaaS groups, Anubis doesn't rely on a single team of hackers to breach every target. Instead, its developers build and maintain the malware, then recruit affiliates through Russian-language cybercrime forums to actually carry out attacks.

What sets Anubis apart is the flexibility of its business model. The group offers negotiable revenue splits to affiliates and, notably, runs multiple monetization tracks beyond a standard encryption-for-ransom scheme. One of these tracks is dedicated specifically to data extortion, allowing affiliates to profit from stolen information even in cases where encryption isn't the primary goal. This structure lowers the barrier to entry for criminals and diversifies how victims can be pressured into paying.

Why Data Extortion Is Replacing Simple Encryption Attacks

For years, ransomware meant one thing: files got locked, and victims paid for a decryption key. That model is fading. Anubis reflects a broader shift in the ransomware economy toward stealing data first and threatening to leak it, often alongside or instead of encrypting files outright.

This matters because encryption alone has a built-in weakness for attackers: a victim with solid backups can simply restore their systems and refuse to pay. Data theft removes that escape hatch. Even if a company recovers its files from backup, the threat of sensitive customer records, financial data, or internal communications being published or sold still hangs over them. Anubis's dedicated data extortion program formalizes this leverage, giving affiliates a way to profit whether or not the ransomware payload ever gets deployed.

This trend echoes what's happened in other recent incidents where stolen data itself becomes the product, as seen when threat actors like ShinyHunters have been observed claiming stolen user data for sale outright rather than relying on ransom negotiations at all. Whether through a ransomware group's leak site or a direct sale on a criminal marketplace, the common thread is the same: your data is the asset, not just a bargaining chip.

How Ransomware Groups Gain Initial Network Access

Affiliate-driven ransomware operations like Anubis don't need to develop sophisticated intrusion techniques from scratch. Instead, they capitalize on known, unpatched vulnerabilities in the software organizations already use to connect remotely to their networks. Remote access tools, including VPN gateways and secure access appliances, remain some of the most attractive entry points because a single compromised device or credential can open the door to an entire corporate network.

This is not a hypothetical concern. Active exploitation has recently been documented in widely used remote-access products, including an authentication bypass vulnerability in Palo Alto Networks' GlobalProtect VPN and zero-day flaws in SonicWall's SMA1000 secure access appliances. These kinds of unpatched, internet-facing systems are precisely the type of low-effort, high-reward access points that RaaS affiliates look for when selecting targets, whether they're deploying Anubis or another ransomware family entirely.

Practical Steps for SMBs and Individuals to Reduce Exposure

Small and midsize businesses are often the most exposed to groups like Anubis, since they frequently lack dedicated security teams but still rely on remote access infrastructure daily. A few concrete steps make a meaningful difference:

  • Apply security patches to VPNs, firewalls, and remote access appliances as soon as they're released. Delayed patching on internet-facing systems is one of the most common ways ransomware affiliates get their first foothold.
  • Enforce multi-factor authentication on all remote access accounts, not just for administrators.
  • Maintain offline or immutable backups, and test restoration regularly. This blunts the encryption side of dual-extortion attacks, though it won't stop data theft.
  • Segment networks so that a single compromised device or account doesn't provide a path to the entire organization.
  • Monitor for unusual outbound data transfers, which can be an early warning sign of data exfiltration before a ransom demand ever arrives.

What This Means For You

Whether you run a small business or simply manage your own home network, the Anubis case is a reminder that ransomware defense can no longer focus solely on backups and recovery. Data extortion means attackers profit from simply having your information, regardless of whether they ever encrypt a single file. That raises the stakes on preventing initial access in the first place, particularly through remote access tools that are frequently targeted because they're internet-facing and, too often, unpatched.

Key Takeaways

Anubis ransomware's flexible affiliate model and dedicated data extortion track illustrate how ransomware-as-a-service groups continue to evolve their monetization strategies. For individuals and organizations alike, the practical response is the same: patch remote access software promptly, use strong authentication, and assume that any data on your network could become leverage if attackers get in. Staying current on vulnerabilities affecting VPNs and remote access appliances is no longer optional maintenance; it's a frontline defense against the kind of intrusion that groups like Anubis depend on.