Anubis is an Android malware family best known as a banking trojan that evolved into a multifunction mobile threat with credential theft, overlay-based phishing, keylogging, SMS abuse, contact theft, audio capture, application and process discovery, and ransomware capabilities. It has been observed abusing Android Accessibility Services, including masquerading as Google Play Protect, to obtain elevated interaction privileges that enable credential harvesting, surveillance, and fraud against targeted applications. Anubis can create overlays to capture credentials from banking and other targeted apps, log keystrokes across applications, enumerate installed applications to identify targets, collect running-process information, steal contact lists, send, receive, and delete SMS messages, and record phone calls and ambient audio. It can also exfiltrate files from compromised devices and modify external storage.
Anubis has been distributed through phishing links in email and through trojanized Android applications delivered outside trusted app stores, including fake contact-tracing and coronavirus-themed apps. It has also been associated with dropper campaigns masquerading as legitimate utilities and system components. Reporting has linked Anubis to campaigns targeting banking and cryptocurrency wallet applications at scale, with private variants reportedly aimed at more than a thousand financial and wallet apps. Source-code leaks of Anubis 2.5 contributed to the proliferation of customized variants and influenced later Android banking malware families, including Alien.
In addition to banking-trojan behavior, Anubis includes a ransomware module capable of encrypting device data for extortion and exfiltrating encrypted files. More recent references also associate the Anubis name with a ransomware/extortion operation claiming opportunistic intrusions, rapid victim listing, data theft, and publication of stolen data when demands are not met. Because the name has been used in both Android banking-trojan and ransomware contexts, Anubis should be treated as an overloaded malware name whose meaning depends on operational context. The strongest consistently supported characterization is an Android banking trojan/infostealer family with broad surveillance, credential-theft, and impact capabilities, including mobile ransomware functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Resecurity tied the group to mass exploitation of internet-facing systems, often via known but unpatched flaws, including: ... SolarWinds Web Help Desk (CVE-2025-26399) ... | An attack by the Anubis ransomware group on a port authority on the Adriatic has been cast as a warning to maritime infrastructure... The Anubis Affiliate Machine Anubis surfaced in December 2024 and launched an affiliate program in February 2025, renting out its toolkit through a ransomware-as-a-service (RaaS) model built around double extortion.
Resecurity tied the group to mass exploitation of internet-facing systems, often via known but unpatched flaws, including: ... The CitrixBleed 2 flaw (CVE-2025-5777) | An attack by the Anubis ransomware group on a port authority on the Adriatic has been cast as a warning to maritime infrastructure... The Anubis Affiliate Machine Anubis surfaced in December 2024 and launched an affiliate program in February 2025, renting out its toolkit through a ransomware-as-a-service (RaaS) model built around double extortion.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In its most recent campaigns, FIN7 has been observed deploying the Python-based Anubis backdoor, which provides full system control via in-memory execution and communicates with its command-and-control infrastructure using Base64-encoded data.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK ID Description T1047 Windows Management Instrumentation
After decoding base64, it uses service to decrypt data that encrypted with rc4 scheme... Here is output of my script to get c2 and key from an Anubis sample.
MITRE ATT&CK ID Description T1059.001 Command and Scripting Interpreter: PowerShell
MITRE ATT&CK ID Description T1059.003 Command and Scripting Interpreter: Windows Command Shell
Once executed, the XLL payload initiates a series of code injection techniques... as one of the security vendors started flagging rundll32-based executions generically, the group was forced to experiment with process injection and alternative staging mechanisms.
A malicious application could create an application overlay window on top of a running legitimate application.
At a first look, it seemed clear that the APK was heavily obfuscated... It seems to mostly rely on generating a variety of random functions to hide the real functionalities of the sample... Most of the strings in the code are generated by using functions implementing a XOR decryption of byte arrays.
The source code also appears to have been merged into one main file with most of the function names being obfuscated, as opposed to the previously separated but clear functionality.
Agent Smith can impersonate any popular application on an infected device, and the core malware disguises itself as a legitimate Google application.
Once executed, the XLL payload initiates a series of code injection techniques... as one of the security vendors started flagging rundll32-based executions generically, the group was forced to experiment with process injection and alternative staging mechanisms.
After loading with DexClassLoader, malware removes the decrypted dex file.
“The Overlay attack is a well-known technique implemented on modern Android banking trojans... This usually takes the form of an imitation app or a WebView launched ‘on-top’ of a legitimate application (such as a banking app).”
Malicious functionality in these trojanized contact-tracing applications includes: ... Keylogging ...
Intercepting, redirecting, sending and deleting SMS messages, to bypass SMS-based 2-factor authentication
arp -a for both remote system discovery (T1018)... nltest /dclist for the remote discovery of the domain controllers (T1018). ping for network connectivity tests to remote systems (T1018).
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
“The Overlay attack is a well-known technique implemented on modern Android banking trojans... This usually takes the form of an imitation app or a WebView launched ‘on-top’ of a legitimate application (such as a banking app).”
Malicious functionality in these trojanized contact-tracing applications includes: ... Keylogging ...
Malicious functionality in these trojanized contact-tracing applications includes: ... Voice, Screen, and Camera recording and exfiltration
another trove of data was found within the clipboard synchronization feature. By copy/pasting between victim and attacker machines, operators exposed some additional TTPs and information surrounding their operations.
Malicious functionality in these trojanized contact-tracing applications includes: ... Voice, Screen, and Camera recording and exfiltration
this malware uses social media to obtain its C2: it downloads the webpage of a photo-less Instagram account. It then extracts the biography field of this account and decodes it using Base64.
Sitnikov was allegedly charged for posting the source code of the Anubis banking trojan on Freedom F0x
77 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
101 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group/family described as compromising victims opportunistically, demanding payment, using decryption keys as leverage, and publishing stolen data when demands are not met.
Referenced only as another ransomware example with a similar RMM-to-encryption pattern.
Ransomware used in an attack against fairlife that allegedly involved data theft and extortion, with attackers threatening to leak stolen data unless payment was made.
Ransomware used in a double-extortion attack, with operators alleging they stole about 1 TB of data from Fairlife’s systems before encrypting systems and later publishing the stolen data after the leak deadline expired.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.