NEWS
Anubis Ransomware’s Wipe Mode Raises the Stakes for Fairlife
Anubis’s wipe-mode malware means paying might not restore Fairlife’s stolen files, a wrinkle bigger than Coca-Cola’s 1TB leak claim alone.
A ransomware crew called Anubis says it stole a terabyte of data from Coca-Cola’s Fairlife dairy unit and encrypted its Nutanix systems, giving executives until Monday to negotiate. Coca-Cola confirmed unauthorized access to Fairlife’s systems in a July 16 filing with securities regulators and said production briefly stopped at the brand’s U.S. plants.
Anubis’s malware carries an optional wipe mode that destroys files beyond recovery even for victims who pay, a feature that upends the basic logic behind most ransomware negotiations.
A Week’s Head Start, by Anubis’s Own Account
On Monday, Anubis added Fairlife to its dark web leak site, formally claiming credit for an attack Coca-Cola had already disclosed without naming a culprit. The group told BleepingComputer, the outlet that first reported the leak-site posting, that it had been inside Fairlife’s network far longer than the public knew.
We attacked their systems a week ago. Just a few days later, they immediately reported the incident without attempting to follow the instructions we left on their network.
Anubis wrote to BleepingComputer. On its leak-site post, the group cast the intrusion as a business proposition: “Why cause a public scene and lose millions in downtime? We are offering you a simple, confidential business solution,” it wrote, adding that “a token agreement is all it takes to have your systems fully operational again within hours.”
Coca-Cola has not confirmed the terabyte figure or named Anubis publicly. The company has said the incident did not affect the safety, production or quality of Fairlife’s dairy products, and that the data under threat came from archived systems, not ones in active operational use.
In its July 16 filing, Coca-Cola said on Fairlife’s behalf that it had “identified unauthorized access by a third party to a portion of its systems, including its production-related systems, in connection with a ransomware event.” Production at Fairlife’s U.S. plants was temporarily suspended as a precaution.
What We Know:
- Coca-Cola’s July 16 regulatory filing acknowledges unauthorized third-party access tied to a ransomware event, and Fairlife briefly paused U.S. production.
- Anubis publicly listed Fairlife on its leak site and set a deadline for negotiations.
What’s Unconfirmed:
- Anubis has posted no sample files or other proof that it actually holds a terabyte of Fairlife data.
- Neither side has disclosed a specific ransom amount, or whether any payment has been discussed.
The Wipe Switch That Breaks the Ransom Math
Anubis encrypts files using an elliptic-curve scheme researchers describe as fast and effectively impossible to break without the attackers’ key. That alone puts it in line with plenty of other ransomware families. What sets it apart is a second, optional mode.
Trend Micro’s researchers found the malware carries a command-line flag that reduces file contents to zero bytes while leaving file names and folder structure untouched, a wipe mode no decryption key can ever undo. “This destructive tendency adds pressure on victims and raises the stakes of an already damaging attack,” Trend Micro’s researchers wrote.
Even when affiliates skip wipe mode, Anubis deletes Windows Volume Shadow Copies, the snapshots Windows keeps for its own file recovery, before encryption begins, closing off the easiest recovery path before a victim even knows what hit them.
The wipe switch is only part of how Anubis squeezes victims. The group also runs a tiered affiliate program, first detailed by cybercrime-intelligence firm KELA, that pays criminals in different ways depending on how far they go, with ransomware affiliates keeping as much as 80% of proceeds.
| Affiliate Track | What They Do | Revenue Share |
|---|---|---|
| Initial access brokers | Sell stolen credentials or a network foothold to other criminals | 50% |
| Data extortion affiliates | Steal files and threaten to leak them, without encrypting anything | 60% |
| Ransomware affiliates | Deploy the full encryptor, and optionally the wiper, on a breached network | 80% |
Fairlife’s case fits the top tier: encryption, a wipe-mode threat and a public leak-site posting, the full package Anubis affiliates are paid the most to deliver.
CitrixBleed 2 Still Cashes In, a Year Later
Investigators have not said exactly how Anubis’s affiliates first got into Fairlife’s network. The group’s broader campaign, though, leans hard on one flaw: CitrixBleed 2, tracked as CVE-2025-5777.
Citrix disclosed the bug on June 17, 2025, and pushed patches within a week. It is a memory-leak flaw in NetScaler ADC and Gateway appliances that lets an attacker steal a live login session without ever entering a password, skipping multi-factor authentication entirely. The flaw carries a severity score of 9.3 out of 10.
Threat-hunting firm ReliaQuest flagged likely active exploitation by June 27. Proof-of-concept code went public July 7. Three days later, the Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog and gave federal agencies a single day to patch, one of the shortest windows the catalog has ever set.
A year on, the flaw still pays off for criminals. Arctic Wolf tracked Anubis affiliates abusing stolen NetScaler sessions well into 2026, and cybersecurity firm Huntress found a separate gang, DragonForce, deployed ransomware in under an hour after exploiting the same bug.
Once inside, Anubis affiliates lean on ordinary IT software to hide in plain sight. Arctic Wolf’s researchers found the group repeatedly using:
- ScreenConnect
- Zoho Assist
- MeshAgent
- Remotely
- UltraVNC
- Total Software Deployment
That software is not malicious by itself, which is exactly the point. Commercial remote-access tools rarely trip alarms built to catch unfamiliar hacking code.
From an Italian Port to America’s Dairy Aisle
Fairlife is not an isolated target. Trend Micro’s research ties Anubis to victims in healthcare, construction and other sectors, in countries including Australia and Canada, since the group became active. Arctic Wolf’s own investigation, published this month, linked Anubis to a fast-growing victim list, one that different write-ups of the same report put at 83 to 91 organizations.
The group’s reach goes well beyond consumer brands. Anubis is also blamed for a $10 million extortion attempt against Italy’s Port of Ancona, hitting maritime infrastructure months before a U.S. dairy processor showed up on its leak site.
Is Anubis Just Sphinx With a New Name?
Largely, yes. Researchers at Arctic Wolf and Trend Micro describe Anubis as the direct successor to a 2024 operation called Sphinx, identifiable by little more than a changed file extension. It is also not the first time Coca-Cola’s name has turned up on a ransomware gang’s leak site.
A Changed File Extension Gave It Away
Anubis first appeared in December 2024 as a rebrand of Sphinx, a switch marked by nothing more dramatic than the extension attached to encrypted files, from .sphinx to .anubis, according to Arctic Wolf. Two months later, on February 23, 2025, someone using the handle “superSonic” advertised a new affiliate structure on the RAMP cybercrime forum, the posting KELA’s researchers used to piece together the group’s revenue splits.
Rebranding lets a ransomware operation shed a name that has drawn law enforcement attention while keeping its code, its affiliates and its playbook intact.
Coca-Cola’s Second Leak-Site Listing in 14 Months
Fairlife’s listing is not Coca-Cola’s first brush with a ransomware leak site. In May 2025, a separate group called Everest claimed an attack on Coca-Cola and published stolen employee data after the company declined to pay.
Two different gangs, fourteen months apart, have now put Coca-Cola data up for public viewing. Neither incident, according to the company, has touched the drinks and dairy products that reach store shelves.
The Countdown Now Reads Monday
Anubis has given Fairlife until Monday, July 27, to reach what it calls a confidential business solution before it says it will publish the files. The company has offered no public timeline of its own.
- Around July 9: Anubis says it first breached Fairlife’s network, according to the group’s own account to BleepingComputer.
- July 16: Coca-Cola discloses unauthorized access tied to a ransomware event in a regulatory filing, without naming an attacker.
- July 20: Anubis lists Fairlife on its dark web leak site, claiming a terabyte of stolen data and an encrypted Nutanix environment.
- July 27: The deadline Anubis has set for Fairlife to begin negotiations before it says it will publish the data.
Coca-Cola has not said whether it will pay. Its files, by the attackers’ own account, have been encrypted for more than two weeks.
Frequently Asked Questions
Is Fairlife Milk Still Safe to Buy?
Coca-Cola has said the ransomware event did not affect the safety, production or quality of Fairlife’s dairy products, and that the data Anubis claims to hold came from archived systems rather than the plant’s active operational environment. Production at Fairlife’s U.S. facilities was briefly suspended as a precaution, while operations in Canada continued without interruption.
What Does Coca-Cola’s 8-K Filing Actually Say?
An 8-K is a disclosure publicly traded companies must file with the U.S. Securities and Exchange Commission after a material event. Coca-Cola’s July 16 filing on Fairlife’s behalf described unauthorized third-party access to systems, including production-related systems, tied to a ransomware event, without naming Anubis or estimating a financial cost.
Did Coca-Cola Pay the Anubis Ransom?
Coca-Cola has not said publicly whether it intends to pay. Anubis set a deadline of Monday, July 27, for negotiations, and as of this writing neither side has confirmed a payment or a published data dump.
Is This Anubis Related to the Android Banking Trojan of the Same Name?
No. Researchers note the ransomware group shares its name with an unrelated Android banking trojan that also carries a ransomware module, but the two are separate pieces of malware built by different operators with no known connection.
Can Anubis Victims Recover Files Without Paying?
It depends on whether an affiliate activated wipe mode. When that command-line flag runs, file contents are reduced to zero bytes and cannot be restored by any decryption key, so backups made before the intrusion, kept offline or immutable, are often the only path back for a victim that will not pay.
-
AI4 weeks agoFable 5 and Mythos 5 Return as US Lifts Anthropic Export Controls
-
AI2 months agoSpaceX’s Google Deal Turns a Rocket Company Into a Cloud Landlord
-
GAMING1 month agoCD Projekt Red Co-CEO: Redemption Arc Isn’t Done, Witcher 4 in 2027
-
AI1 month agoOracle Cuts 21,000 Jobs in a Year, Cites AI in 10-K Filing
-
CRYPTO2 months agoXPL Rallies 30% Ahead of Plasma One Card Tier Launch
-
APPS2 months agoDGO App Brings Rs 549 Mobile Pass for FIFA World Cup 2026 in Nepal
-
AI2 months agoMoonshot AI Targets $30 Billion in China’s Fastest AI Funding Sprint
-
NEWS2 months agoGoogle Search Profiles Build a Follow Graph Inside Discover
