Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Multiphysics simulation of electromagnetic heating for surgical infection treatment in knee replacement

    August 6, 2025

    Walmart employee’s ‘magic’ side hustle is more than $ 1 million

    August 6, 2025

    How not a North Korean to spy it

    August 6, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Anubis Ransomware adds vipers to destroy files beyond recovery
    Security

    Anubis Ransomware adds vipers to destroy files beyond recovery

    PineapplesUpdateBy PineapplesUpdateJune 14, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Anubis Ransomware adds vipers to destroy files beyond recovery
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Anubis Ransomware adds vipers to destroy files beyond recovery

    Anubis Ransomware-AS-A-Service (RAS) operation has added a wiper module to its file-econstimge malware that destroys targeted files, yet makes recovery impossible even after paying ransom.

    Anubis (the same name with a ransomware module not to be confused with Android Malware) is a relatively new RAAS that was first seen in December 2024, but became more active at the beginning of the year.

    On 23 February, the operators announced an affiliated program on the ramp forum.

    A Banana report At that time it was explained that Anubis introduced 80% of his income to ransomware colleagues. Data extortion affiliation was offered 60%, and initial access brokers were offered a deduction of 50%.

    Currently, the forced recovery of anubis on the dark web lists only eight victims, indicating that this can increase the amount of attack after strengthening confidence in the technical aspect.

    On that front, a trend micro report published yesterday involves evidence that the operators of the option are actively working on adding new features, an unusual a file-wipe function.

    Researchers found the wiper into the latest veil samples, and believe that this feature was introduced to pay quickly instead of early paying to increase the pressure on the victim or to make a quick payment to ignore them completely.

    “What further separates Annabis from other RAAS and lends an edge for its operation, it is the use of a file wiping facility, which is designed to break the recovery efforts even after encryption,” Trend Micro explains,

    “This devastating tendency puts pressure on victims and already enhances the bet of harmful attacks.”

    The disastrous behavior is activated using the command-line parameter ‘/vipmod’, which requires key-based authentication to release.

    Anubis' Wipe Mode
    Anubis’ Wipe Mode
    Source: Trend Micro

    When active, the viper erases all file materials, reducing its size to 0 KB by retaining the file name and structure.

    The victim will still look at all the files in the required directors, but their content will be uninterrupted, which will make recovery impossible.

    Encryption (top) and subsequent files before (below)
    Encryption (top) and subsequent files before (below)
    Source: Trend Micro

    Analysis of trend micro suggests that Anubis launches supports several commands, including the target path for privilege height, directory exclusion and encryption.

    Important systems and program directors are excluded in default form to avoid submitting a fully unusable system.

    The ransomware removes volume shade copies and eliminates procedures and services that can interfere with the encryption process.

    The encryption system uses ECIES (elliptical curve integrated encryption scheme), and researchers noted implementation similarities for evilbate and prince ransomware.

    Encrypt files are added to the ‘.anubis’ extension, an HTML ransom note is dropped on the affected directions, and also makes an effort (failed) to replace the malware desktop wallpaper.

    Thne Anubis Ransom Note
    Anubis ransom note
    Source: Trend Micro

    Trend Micro noticed that the attacks of Aubis begins with the fishing email that carry malicious links or attachments.

    There is a complete list of indicators of the agreement related to the optional attacks (IOCs) Available here,


    Tines needle

    Patching meant complex scripts, long and endless fire drills. No more.

    In this new guide, the tines break down how it is leveling with modern organ automation. Patch fast, reduce overhead, and focus on strategic tasks – no complex script is required.

    adds Anubis destroy files Ransomware recovery vipers
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleBurner emails are not just for spam – I use them for these 6 easy purposes
    Next Article iOS 26 will fit the carplay to better match the size of your car screen
    PineapplesUpdate
    • Website

    Related Posts

    Security

    How not a North Korean to spy it

    August 6, 2025
    Security

    My new favorite kitchen holder can carry up to 14 keys (and is trackable by phone)

    August 6, 2025
    Security

    New ghosts for C2 operations misused strategy and call Microsoft teams

    August 6, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    Multiphysics simulation of electromagnetic heating for surgical infection treatment in knee replacement

    August 6, 2025

    Walmart employee’s ‘magic’ side hustle is more than $ 1 million

    August 6, 2025

    How not a North Korean to spy it

    August 6, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.