Anubis is an Android banking trojan with credential-theft, surveillance, and ransomware capabilities. It enumerates installed applications to identify targets and displays deceptive overlays that capture credentials for targeted applications. Its keylogger can capture input across installed applications. Anubis also steals contact lists, sends, receives, and deletes SMS messages, records phone calls and microphone audio, and initiates calls. A ransomware module encrypts device data for extortion, and the malware can exfiltrate files encrypted by that module.
Anubis has been distributed through phishing links in email and malicious applications masquerading as contact-tracing tools. It impersonates Google Play Protect when requesting Accessibility service privileges and disguises additional malicious application installations as legitimate system updates. These behaviors combine financial credential theft with broader collection and control of compromised Android devices.
The Android banking trojan is distinct from the unrelated Anubis ransomware-as-a-service operation that emerged in 2025 and targets enterprise Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“Resecurity is sharing a case study with an analysis of Anubis Ransomware affecting one of the major port authorities in the EU.”
“Resecurity is sharing a case study with an analysis of Anubis Ransomware affecting one of the major port authorities in the EU.”
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Resecurity is sharing a case study with an analysis of Anubis Ransomware affecting one of the major port authorities in the EU.”
Analysts from Microsoft identified a consistent pattern after access was gained, even when attacks ended with Qilin, DragonForce, Anubis or BERT ransomware.
In its most recent campaigns, FIN7 has been observed deploying the Python-based Anubis backdoor, which provides full system control via in-memory execution and communicates with its command-and-control infrastructure using Base64-encoded data.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK ID Description T1047 Windows Management Instrumentation
After decoding base64, it uses service to decrypt data that encrypted with rc4 scheme... Here is output of my script to get c2 and key from an Anubis sample.
MITRE ATT&CK ID Description T1059.001 Command and Scripting Interpreter: PowerShell
MITRE ATT&CK ID Description T1059.003 Command and Scripting Interpreter: Windows Command Shell
Once executed, the XLL payload initiates a series of code injection techniques... as one of the security vendors started flagging rundll32-based executions generically, the group was forced to experiment with process injection and alternative staging mechanisms.
A malicious application could create an application overlay window on top of a running legitimate application.
At a first look, it seemed clear that the APK was heavily obfuscated... It seems to mostly rely on generating a variety of random functions to hide the real functionalities of the sample... Most of the strings in the code are generated by using functions implementing a XOR decryption of byte arrays.
The source code also appears to have been merged into one main file with most of the function names being obfuscated, as opposed to the previously separated but clear functionality.
Agent Smith can impersonate any popular application on an infected device, and the core malware disguises itself as a legitimate Google application.
Once executed, the XLL payload initiates a series of code injection techniques... as one of the security vendors started flagging rundll32-based executions generically, the group was forced to experiment with process injection and alternative staging mechanisms.
After loading with DexClassLoader, malware removes the decrypted dex file.
“The Overlay attack is a well-known technique implemented on modern Android banking trojans... This usually takes the form of an imitation app or a WebView launched ‘on-top’ of a legitimate application (such as a banking app).”
Malicious functionality in these trojanized contact-tracing applications includes: ... Keylogging ...
Intercepting, redirecting, sending and deleting SMS messages, to bypass SMS-based 2-factor authentication
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
“The Overlay attack is a well-known technique implemented on modern Android banking trojans... This usually takes the form of an imitation app or a WebView launched ‘on-top’ of a legitimate application (such as a banking app).”
Malicious functionality in these trojanized contact-tracing applications includes: ... Keylogging ...
Malicious functionality in these trojanized contact-tracing applications includes: ... Voice, Screen, and Camera recording and exfiltration
another trove of data was found within the clipboard synchronization feature. By copy/pasting between victim and attacker machines, operators exposed some additional TTPs and information surrounding their operations.
Malicious functionality in these trojanized contact-tracing applications includes: ... Voice, Screen, and Camera recording and exfiltration
this malware uses social media to obtain its C2: it downloads the webpage of a photo-less Instagram account. It then extracts the biography field of this account and decodes it using Base64.
Sitnikov was allegedly charged for posting the source code of the Anubis banking trojan on Freedom F0x
78 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
110 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family deployed in attacks attributed to Storm-2570. Its use is associated with the affiliate's recurring post-compromise techniques, including credential theft and data exfiltration before ransomware deployment.
Ransomware payload deployed by Storm-2570; activity preceding deployment includes Microsoft Defender tampering and data theft.
Ransomware-as-a-service that encrypts files with an ECIES-based implementation, appends the .anubis extension, deletes shadow copies, stops services, and uses double extortion. Its /WIPEMODE capability overwrites file contents, leaving files at 0 KB and preventing recovery even after encryption.
Ransomware associated in the article with the alleged compromise of Fairlife and theft of over 1 TB of data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.