Quick Summary
AllegedExecutive Summary
Anubis ransomware group added Scholle IPN / SIG, a global packaging manufacturer based in Germany, to its leak portal on August 18, 2026. The company operates under the domain sig[.]biz. This targeting aligns with Anubis’s documented activity, which has focused on the Manufacturing, Healthcare, and Retail & E-Commerce sectors over the preceding 60 days. The group’s primary victim countries during this period have been the United States, Germany, and France. The targeting of Scholle IPN / SIG fits the Anubis group’s typical pattern, particularly given its status as a Germany-based multinational operating in the industrial packaging sector. Recent Anubis victims with similar manufacturing profiles include Cleaver-Brooks, Winn-Dixie, and BLACKBURN’S, underscoring the group’s continued focus on this industry.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry for the domain sig[.]biz revealed a significant exposure profile. Ten employee credentials were found associated with the organization’s infrastructure, including those related to Microsoft 365 / Azure identity providers (login.microsoftonline[.]com), Office 365 mail (smtp.office365[.]com), a Citrix remote-access gateway (citrix.sig[.]biz), an internal collaboration system (eroom.sig[.]biz), and an internal manufacturing system (chneuarubacp.sig[.]biz). Microsoft Yammer was also noted. In addition to these direct organizational credentials, five further records indicated credentials for @sig[.]biz on third-party platforms. The timestamps for these records span from June 20 to August 10, 2026, covering a 51-day period. The presence of multiple usernames appearing repeatedly across different dates suggests either ongoing infection or a lack of credential rotation. While the stealer-log data does not definitively confirm that Anubis directly utilized these compromised credentials for their attack, the exposure of Citrix VPN and Azure identity information over a 51-day period without rotation is a recognized precursor to ransomware deployment. Ransomware operators frequently acquire validated Citrix credentials from underground marketplaces to facilitate lateral movement before executing their payloads. Organizations should rotate all identified @sig[.]biz credentials, revoke active Citrix sessions, audit Microsoft 365 sign-in logs from June 20, 2026, and review endpoint detection data for compromised accounts.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.