Threat Actor

Anubis

Properties

summary
Threat actors associated with the Anubis ransomware operation were observed exploiting the Citrix Bleed 2 vulnerability (CVE-2025-5777) to gain initial access to victim environments.
first_seen
2026-07-06T04:00:29.739771+00:00
last_seen
2026-07-06T04:00:29.739771+00:00
created_at
2026-07-06T04:00:29.739771+00:00
mention_count
1
evidence_url
https://thehackernews.com/2026/07/ransomware-groups-turn-to-citrix-bleed.html
resolution_basis
exact name match to existing RansomwareGroup/RansomGroup 'anubis'
target
multiple sectors
resolution_method
automatic
provenance
news-scan
rule_version
2026-09-12.1
resolution_rule
R2_name_matches_known_actor
resolved_at
2026-09-12T04:34:24+00:00
scan_confidence
0.8
suspected_origin
unknown

Explore this actor's full graph with Ninja Signal

Anubis — Threat Actor Profile — Ninja Signal | Ninja Signal