Anubis can wipe your data instead of holding it for ransom

Peer Review

Gartner brand name text logo in white with registered trademark symbol.
5-star rating
4.8

Proven Trust

Dark blue circle with two overlapping checkmarks, one green and one light blue.
ISO 27001 text with a globe outline symbol on a black background.
2025 winner badge for Cyber Security Excellence Awards with gold and black design.

Anubis pairs double extortion with an irreversible data-wipe mode. See how it operates and how to stop it before that decision is made.

Get Guide

Paying doesn't guarantee your data comes back

Success here means shutting down access before Anubis decides whether to encrypt, wipe or simply extort, not negotiating after that decision's already made.

  • Exploits CitrixBleed 2 and similar edge vulnerabilities, or buys infostealer-harvested credentials
  • Can trigger an irreversible wipe mode instead of encryption, removing recovery as a guaranteed outcome
  • Offers journalists early access to stolen data to sustain pressure if unpaid

Who This Guide is For

CISO / Head of Security

Anubis's wipe mode means there's no decryption fallback. This guide covers the identity controls that stop access being brokered in the first place.

SOC Manager / Security Operations Lead

Data theft happens before the encrypt-or-wipe decision. This guide explains where to catch it during exfiltration, not after.

IT Director / Head of IT

CitrixBleed 2 and purchased credentials are the entry points. This guide sets out the patching and credential checks that shut both down.