Anubis Ransomware Deploys “Wipe Mode” and Targets U.S. Healthcare Providers
What Happened — The Anubis ransomware‑as‑a‑service (RaaS) group, rebranded from “Sphinx” in late 2024, encrypts files with a “.anubis” extension and can optionally invoke a “wipe mode” that overwrites files to zero‑byte size. In July 2026 the group breached Mississippi‑based Singing River Health System, exfiltrating 293 GB of patient data (PII, medical records, bank details) and threatening publication. Entry vectors reported include spear‑phishing emails and exploitation of the CitrixBleed 2 vulnerability (CVE‑2025‑5777).
Why It Matters for Compliance & Audit Readiness
- SOC 2 CC6.1 (Logical Access) and CC7.2 (Incident Management) require documented controls against phishing and unpatched vulnerabilities; Anubis shows the cost of gaps.
- Continuous evidence of security‑awareness training and phishing‑simulation results is essential audit proof that the organization mitigates the most common ransomware entry point.
- Demonstrable, tested backup and recovery processes satisfy SOC 2 CC5.2 (Backup) and provide a defensible posture when ransomware attempts data‑wipe attacks.
Who Is Affected – Primarily U.S. healthcare providers; secondary targets include manufacturing, construction, legal, and financial services.
Recommended Actions
- Map phishing‑email controls and vulnerability‑patch management to SOC 2 CC6.1/CC7.2 and collect continuous monitoring evidence.
- Verify that all critical systems are patched for CVE‑2025‑5777; document the patch‑status as audit evidence.
- Run a security‑awareness simulation, record participation, and remediate gaps before the next audit window.
- Validate that immutable, offline backups exist and can be restored within RTO/RPO targets.
Source: Fortra Blog – Anubis ransomware
Technical Notes – Attack vectors: spear‑phishing (malicious attachments/links) and exploitation of CitrixBleed 2 (CVE‑2025‑5777). Payload adds “.anubis” to encrypted files; optional wipe mode overwrites data to zero bytes. Stolen data includes SSNs, DOB, health‑insurance numbers, diagnostic images, and banking details.