Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We named these malicious apps AnubisSpy (ANDROIDOS_ANUBISSPY) as all the malware’s payload is a package called watchdog.
We named these malicious apps AnubisSpy (ANDROIDOS_ANUBISSPY) as all the malware’s payload is a package called watchdog.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
To evade traffic inspection, all keywords in the request body are replaced based on protocol_strings specified in the configuration file.
An AnubisSpy variant... poses as a promotional app (SisiFans)... SwiftClinic... masqueraded as a patient registration application for dental clinics.
AnubisSpy can also self-destruct to cover its tracks. It can run commands and delete files on the device...
We construe AnubisSpy to be linked to the cyberespionage campaign Sphinx (APT-C-15) based on shared file structures and command-and-control (C&C) server as well as targets.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android spyware used in a cyberespionage campaign targeting Arabic-speaking users and Middle Eastern countries. It steals SMS, photos, videos, contacts, email accounts, calendar events, and browser history; can take screenshots, record audio and calls, spy via installed apps, encrypt and exfiltrate collected data to C2, self-destruct, run commands, delete files, and install or uninstall APKs.
Android spyware used in a mobile cyberespionage campaign targeting Arabic-speaking users and Middle Eastern countries. It steals SMS, photos, videos, contacts, email accounts, calendar events, browser histories, location data, screenshots, audio including calls, and data from apps such as Skype, WhatsApp, Facebook, and Twitter; encrypts and uploads the data to C2; can execute commands, manipulate APKs, and self-destruct.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.