The Anubis ransomware-as-a-service (RaaS) has added a new file-wiping module, making data recovery impossible even after ransom payment. This destructive feature aims to pressure victims into quick payment and increases the threat level of Anubis attacks. #Anubis #Ransomware #DarkWeb
Keypoints
- The Anubis RaaS has introduced a file-wiper module to its malware, damaging data irreversibly.
- Its operators launched an affiliate program offering up to 80% of proceeds, attracting more threats.
- The destructive wipe mode can be activated with a command-line parameter, erasing file contents.
- Anubis primarily spreads through phishing emails with malicious links or attachments.
- Despite the added wipe feature, Anubis maintains typical encryption, dropping a ransom note and extending damage potential.