Trend Micro reported that the AnubisSpy Android spyware family targeted Arabic-speaking users across the Middle East by posing as benign mobile apps on Google Play and third-party marketplaces. The lures were often written in Arabic and themed around Egypt and regional sociopolitical topics, including apps such as SisiFans and SwiftClinic. Researchers linked the malware to the Sphinx (APT-C-15) cyberespionage campaign through shared command-and-control infrastructure, similar file structures, a common JSON decryption method, and overlapping regional targeting.
Once installed, AnubisSpy could exfiltrate SMS messages, contacts, emails, calendar events, browser history, photos, videos, location data, screenshots, and device information, while also collecting communications from apps including Skype, WhatsApp, Facebook, Twitter, Viber, and Gmail. The spyware also supported command execution, APK installation and removal, audio and call recording, and self-deletion after sending encrypted data to its command-and-control server, with some functions expanded on rooted devices. Trend Micro said development artifacts dated the operation to at least 2015, and Google removed the identified apps after disclosure and updated Google Play Protect to detect them.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
The latest analyzed AnubisSpy variant carried a signing timestamp from May 2017. Across the campaign, Trend Micro identified at least seven malicious apps signed with the same fake Google certificate.
Trend Micro reported that the earliest analyzed AnubisSpy sample was signed in June 2015. The malware was distributed through malicious Android apps on Google Play and third-party marketplaces.
Hardcoded agent version strings indicated the AnubisSpy Android spyware apps were developed as early as April 2015. The apps were written in Arabic and themed around Egypt and Middle Eastern news or sociopolitical topics.
Trend Micro said the related Sphinx cyberespionage campaign was active between June 2014 and November 2015, with malware timestamps suggesting activity may have started as early as 2011. Sphinx primarily used watering-hole delivery via social media and customized njRAT payloads.
Google updated Google Play Protect to detect and take action against the verified policy-violating AnubisSpy apps. This followed Trend Micro's disclosure of the malicious applications.
Following disclosure, Google removed the identified AnubisSpy applications from Google Play. One masquerading app, SisiFans, had accumulated 150 installs before removal.
After analyzing the spyware-laced apps, Trend Micro disclosed the identified AnubisSpy applications to Google. Coordination with Google also showed the apps had been installed in several Middle Eastern countries.
Trend Micro assessed that the Android spyware family AnubisSpy was linked to the Sphinx (APT-C-15) cyberespionage campaign. The linkage was based on a shared command-and-control server at 86.105.18.107, similar file structures, shared JSON decryption technique, and overlapping Middle East targeting.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.