ANUBIS ransomware has targeted Quest Health Solutions, exfiltrating 239 GB of sensitive operational data. Operating under a dual-threat encryption and wiping model, this Go-based malware poses severe risks to healthcare infrastructure. Explore the technical attack chain, SIEM detection rules, and containment steps.


Spear-phishing or unpatched VPN/RDP
Go executable, token manipulation
Stops DB/backup services, deletes VSS
Stages and exfiltrates 239 GB of data
ECIES encryption or destructive /WIPEMODE
If your team may be exposed to a similar threat, FemtoSec can help validate blast radius, prioritize remediation, and connect the issue to a practical security program.
This original source is hosted on the Tor network. Use Tor Browser to open it, and treat the forum as untrusted while reviewing the post.
Onion URL
http://om6q4a6cyipxvt7ioudxt24cw4oqu4yodmqzl25mqd2hgllymrgu4aqd.onion/r/zs0kJn+TWO+EWnaEbyIpQaCT835tcHS1M1bX8cYZtRsoiruZcRaSFoZmfT7PLjbzYqWqL3UuLe+waxoy4oJUpWUklxb2Nj