NEWS
Anubis Phished Ancona While Seized Tankers Ran AnyDesk
Anubis demanded $10 million after an IT-side breach at Italy’s Ancona port authority, while Coast Guard teams found AnyDesk on seized dark-fleet tankers.
Anubis posted Italy’s Central Adriatic Port Authority on its leak site in January 2026 and demanded $10 million in Bitcoin. The authority that runs the Port of Ancona said the December 11, 2025 intrusion took 2% of its files.
June recaps still named Croatia’s Port of Ploče. The operator that published a notice is in Ancona, and the Coast Guard’s own boarding notes on seized tankers describe AnyDesk and pirated Windows, not a private cell network.
The Port Authority in Ancona Took the Breach
The legal name is Autorità di Sistema Portuale del Mare Adriatico Centrale. It is the public body for Ancona and neighbouring central Adriatic ports, not Luka Ploče in southern Croatia. Ancona moved 9,675,225 tonnes of cargo in 2025, up 2% from 2024, so the target sits on a live trade stack, not a quiet backwater.
The authority said the theft happened while it was moving data onto Italy’s Polo Strategico Nazionale, the state cloud built to lock down strategic systems. AgID, the Agency for Digital Italy, sent a letter on January 14, 2026 naming Anubis. The authority’s January 16 notice put the loss at 2% and said Postal Police and the data-protection authority had been told.
Resecurity, a U.S. threat-intelligence firm, published a case study on June 11, 2026 that reconstructed a different scene: thousands of files locked, cargo tracking and customs processing frozen, and ships sent to other harbours. That write-up is the source of the $10 million figure that then travelled through industry notes. The two accounts can both be true in parts. A small slice of a file store can still include staff records and safety plans, and an IT outage can stall a port without anyone touching a crane controller.
THE ANCONA CLOCK
- December 11, 2025: The authority dates the intrusion to this day, during the national-cloud migration.
- January 14, 2026: AgID tells the authority the crew is Anubis, a name the body says it already knew.
- January 16, 2026: Ancona posts the 2% notice and says unions and staff have been briefed.
- June 11, 2026: Resecurity publishes the $10 million Bitcoin demand and the IT-side reconstruction.
A Japanese practitioner reading that reconstruction flagged the sequence itself: a malicious mail attachment that installs ransomware, then a later hop across the network, reads like two jobs glued into one paragraph. Resecurity still holds that a spear-phishing email to port staff opened the door, then privilege escalation and unpatched holes did the rest.
Two Percent of the Files and a $10 Million Clock
Ancona’s public line is narrow. Backups held the rest, most of what left was already public or about to be, and employee records were the exception that reached a leak site. Resecurity’s line is wider: contracts, staff files, and, more awkwardly, safety plans and how the port runs security. That last pile is useful to people who want to move goods past a gate, not only to people who want Bitcoin.
ANCONA’S NOTICE VERSUS THE CASE STUDY
| Point | Port authority | Resecurity |
|---|---|---|
| Data taken | 2% of holdings | Thousands of files, including contracts and staff records |
| What froze | Not described as a shutdown | Cargo tracking, sailing lists, customs processing |
| Money asked | Not stated in the notice | $10 million in Bitcoin, seven days to pay |
| Machines hit | Data store during a cloud move | IT accounts, including Office 365 and Azure, not OT gear |
Resecurity is explicit on the last row. The crew did not need to attack the programmable kit that drives cranes, pumps, or gates. Insecure cloud logins were enough, it said, to produce knock-on effects in the physical yard. That is a cheaper trick than a nation-state strike on industrial controls, and it is also harder for a board to brief, because the broken thing looks like email.
John Strand, owner of Black Hills Information Security, put the business logic in one line: crews pick entry points that spread pain across several industries, which raises both the chance of a payment and the size of the bill. A port authority sits upstream of shipping lines, truckers, customs brokers, and the factories waiting on the cargo. Encrypt the office layer and all of those clocks start at once.
Anubis Pays Affiliates 80 Percent to Encrypt
Anubis in this story is not the old Android banking trojan. Arctic Wolf tracks it as a ransomware-as-a-service brand that emerged in late 2024 from the Sphinx family, with a public affiliate drive on the RAMP forum on February 23, 2025. Operators used the handles superSonic on RAMP and Anubis__media on XSS and Exploit. Resecurity says the program has been active since at least December 2024 and that the crew claimed more than $20 million in revenue while refusing victims in the former USSR and BRICS bloc.
HOW THE CUTS RUN
- Encryption jobs: Affiliates keep 80% when they deploy the locker.
- Data-only shakedowns: The cut falls to 60% if the play is stolen files without encryption.
- Access brokers: A 50% split for people who only sell a foothold.
- Bulk data buys: The desk said it would purchase unpublished hauls of 40 GB or more from firms in the United States, Canada, the European Union, and Australia.
A public leak-site tracker, RansomLook, listed 110 Anubis posts on September 9, 2026, with six in the prior 30 days. The Ancona listing is one row in a volume business. Arctic Wolf’s 2026 case work, separate from Ancona, found affiliates walking in with CitrixBleed 2 and valid VPN logins, then living inside ScreenConnect, Zoho Assist, MeshAgent, and other remote-admin tools that look like ordinary IT. Some crews now also ride the client’s own AI assistants once they are inside, which hides the later stages in software the victim already trusts.
That pattern matters more than the brand name on the ransom note. Ancona did not need a bespoke worm. It needed one mailbox, or one stale remote-access box, and a locker that affiliates already knew how to run.
What Coast Guard Teams Found After They Boarded
The second half of the June scare was not a port. U.S. Coast Guard Cyber Command’s fifth 2025 marine cyber trends report is the artifact. From December 2025, cyber protection teams flew onto dark-fleet tankers with boarding parties, took “cyber positive control” of the digital terrain, and wrote down what they saw. Rear Adm. Jason Tama, who commands Coast Guard Cyber Command, said those joint jobs with law-enforcement teams and the Department of War are how the service now holds seized ships.
Cyber threats in the maritime domain are evolving.
Read our 2025 Cyber Trends and Insights into the Marine Environment Report to learn more about compelling topics like AI in maritime defense, threats to Terminal Operating Systems, and how the Coast Guard deployed “cyber…
— U.S. Coast Guard (@USCG) June 16, 2026
MyCG, the Coast Guard’s own newsroom, stated the irony in plain language: the same kit these ships use to hide leaves them open. On home waters, the same report said, the boring vector still wins. Cyber protection teams broke into an operator’s system 53% of the time with a phishing mail. Demand for operational-technology testing rose 35%. In seven missions against networks that had bought AI defence platforms, a well-tuned tool spotted a simulated attack in 30 seconds and a poorly set one saw nothing. One live case in the report was a fake CEO invoice that walked off with nearly $50,000.
KIT ON THE SEIZED TANKERS
- Remote admin: AnyDesk, TeamViewer, and ScreenConnect left running with nobody watching, so an owner or anyone with the password could reach the ship from shore.
- Identity tricks: Several AIS transponders on one hull, plus marine test software on a laptop feeding fake NMEA-0183 sentences through a custom-soldered cable into the AIS data port.
- Pirated nav pile: Cracked Windows via Ratiborus KMS, pirated ECDIS and route software pulled from a Russian-language torrent board, and at least one workstation with Lumma Stealer on it.
- Live wipe: Shore-side admins tried to delete data remotely while U.S. teams were already aboard.
- Thin air gap: Core steering and engine links were still mostly serial and separate, but USB updates and laptops clipped to ECDIS or engine-room gear sometimes bridged that gap.
That list is messy, cheap, and dangerous in a different way from a purpose-built spy net. A tanker carrying crude with an unattended remote-desktop session is a spill and fire problem for the boarding team and for whoever sits down-current. It is also a problem the owner can trigger from a laptop in another country, which is the point of the install.
AnyDesk Was Already Running When the Teams Came Aboard
Josh Marpet, senior product security consultant at Finite State, read the tanker findings as the maritime cousin of cartel radios. Drug groups have spent years on private cell nets, radar, and LiDAR to keep talking when the wires are tapped, he said, and unsanctioned oil work at that grade would imply money, time, and a cyber unit with signals-intelligence reach.
It’s not simple to set up a private cell network across miles of water. It’s not simple, cheap or easy to set up private Internet across large expanses of land and sea.
Josh Marpet, Senior Product Security Consultant, Finite State
WHERE THE READINGS SPLIT
- Marpet’s frame: Private comms at this scale look like nation-state blockade-running, with a scouting layer to vector tankers around search ships.
- The boarding notes: Persistent AnyDesk and TeamViewer, extra AIS boxes, a soldered test cable, and pirated charts. Commodity tools, badly kept.
Both can describe pieces of a fleet that is not one fleet. Some hulls may carry better radios than the ones Coast Guard teams wrote up. The hulls they did write up were running the same remote-admin brands Anubis affiliates drop in corporate networks. In August 2026, Coast Guard Cyber Command briefers were still on this beat at DEF CON 34, in a talk on hunting the dark fleet in cyberspace, which is a sign the boarding program did not end with the June report.
The Bella 1 case shows how the physical chase and the digital mess sit together. Avtandil Kalandadze, 47, master of that tanker, pleaded guilty on June 12, 2026 in Washington to refusing Coast Guard orders during a multi-week pursuit. The plea says the ship moved 1.8 million barrels of Iran-origin oil to Asia, sailed with AIS off, hid its name during a ship-to-ship transfer, and, after USCGC Munro intercepted it in December 2025, fled until a January 7, 2026 seizure. Destroying records onboard was part of the flight. Remote wipes on other hulls are the same instinct with a better mouse.
Staff Files and Safety Plans Left the Building
The people with skin in Ancona are not only the authority’s IT shop. Employee records on a leak site are a gift for anyone who wants to phish the next shift, impersonate a planner, or recruit a gate clerk. Safety plans and security-operations notes, if Resecurity’s haul list is right, travel even farther. Smuggling groups pay for that paper. So do competitors bidding on terminals. So does anyone who wants to know when a camera is blind.
Cargo owners sitting behind those 9,675,225 tonnes feel a different delay. If tracking, slot lists, and customs files go dark, the yard can still have working cranes and still fail to clear a ship. Resecurity’s historical table is the long version of that failure: Maersk’s 2017 NotPetya hit, Nagoya’s 2023 LockBit stoppage, Lisbon the same year, Vigo in 2026. Ancona’s official story is that this round stayed inside 2%. The demand on the table was still sized for a full stop.
Boarding teams are the hidden party on the tanker side. A ship that can be reached with TeamViewer while a helicopter is on the deck is a ship that can have its logs wiped, its identity flipped, or, if someone is reckless with tank and pump software, its safety margins cut while people are climbing the ladder. Coast Guard cyber teams now treat that as part of the seizure, not a follow-up ticket for a vendor.
Anubis will keep listing victims because the affiliate math still works. Dark-fleet operators will keep bolting extra AIS boxes onto old hulls because hiding still pays. The June mashup that put a Croatian name on an Italian breach, and a spy-radio story on a pile of remote-desktop apps, made both jobs sound rarer than they are. The mailbox and the AnyDesk session are the parts that already scale.
Frequently Asked Questions
Which Ports Sit Under the Adriatic Authority?
The Central Adriatic Sea Port Authority covers Ancona, Falconara Marittima, Ortona, and Vasto for cargo, with Pesaro in the passenger figures. Together those cargo ports moved 11,418,101 tonnes in 2025, up 1% from 2024, and Ancona is the heavy end of that system rather than a standalone municipal dock.
Does Anubis Target Russia or BRICS Countries?
Resecurity says the operators told partners they do not go after victims in the former USSR or BRICS countries, and that they buy unpublished data hauls of 40 GB or more from firms in the United States, Canada, the European Union, and Australia. That exclusion is a business rule, not a technical limit.
When Did U.S. Coast Guard Marine Cyber Rules Take Effect?
The Coast Guard published a final rule on January 17, 2025 that sets baseline cyber duties for the marine transportation system, including a written Cybersecurity Plan and a named Cybersecurity Officer, and that rule took effect on July 16, 2025, months before the dark-fleet boarding wave in December.
What Was Anubis Called Before the RAMP Launch?
Arctic Wolf treats Anubis as a late-2024 rebrand of Sphinx ransomware, with the on-disk extension changing from.sphinx to.anubis, and the new brand’s affiliate program going up on RAMP on February 23, 2025. The Android banking malware that also uses the Anubis name is a separate family.
-
AI3 months agoFable 5 Came Back Under a Commerce On-Off Switch
-
AI4 months agoGoogle’s SpaceX GPU Lease Has a Sept. 30 Deadline
-
CRYPTO4 months agoPlasma One’s XPL Locks Face a 1.81 Billion Cliff
-
APPS4 months agoDGO’s Rs 549 World Cup Pass Cost Fans Sleep and Data
-
AI4 months agoMoonshot AI’s $30 Billion Ask Became a $35 Billion Close
-
NEWS4 months agoColorOS 17 Device List Spans Oppo, OnePlus and Realme
-
GAMING4 months agoXbox Cuts 3,200 Jobs After Five Years of Thin Returns
-
GAMING3 months agoThe RTX 4050 Under Rs 70,000 Hides a Wattage Gap
