Anubis

Malware

⚠️ Overview

Anubis is a multifunctional Android banking Trojan first identified in 2016 by Kaspersky Lab, attributed to the Russian-speaking developer group known as "Cron" that also operated the Cron botnet. It belongs to the category of banking Trojans, remote access tools (RATs), and ransomware, capable of stealing financial credentials, exfiltrating sensitive data, locking devices, and demanding ransom payments.

🔧 Technical Capabilities

Anubis leverages overlay attacks to capture login credentials from over 300 financial applications, using Android's Accessibility Service to automate clicks, intercept SMS two-factor authentication codes, and grant itself additional permissions. It establishes command-and-control (C2) communication over HTTP/HTTPS, employing a domain generation algorithm (DGA) to rotate infrastructure and avoid blocking. Persistence is achieved through abuse of Device Administrator privileges, reinstallation after removal via a dropped APK, and reacting to package removal broadcasts. Evasion techniques include heavy code obfuscation, anti-emulation checks that detect sandbox environments, and dynamic loading of DEX payloads from encrypted assets. The malware also supports keylogging, screen recording, remote control via a VNC-like module, and the ability to update its configuration dynamically—capabilities documented in MITRE ATT&CK for Android (S1508) and in a 2017 analysis by Kaspersky's Igor Kuzmenko.

📜 History & Notable Incidents

First surfaced in 2016 as a private botnet, Anubis gained widespread attention in 2017–2018 through campaigns targeting European banks, notably in Turkey, Poland, and Germany, with over 180 financial apps impersonated. In 2019, its source code was leaked on underground forums, spawning a malware-as-a-service economy and dozens of variants—including the "Anubis 2.0" and "Anubis 3.0" updates. High-profile incidents include attacks on cryptocurrency exchanges (e.g., Binance lookalike phishing) and the use of Anubis as ransomware in 2020, locking devices and demanding Bitcoin payments. Law enforcement actions include a 2021 coordinated takedown of 12 C2 servers by the Turkish National Police with Interpol support, as reported by ThreatFabric.

🔍 Detection Indicators

Known file hashes include SHA256 values for variant 4.0 documented by ThreatFabric, such as 8F2C... and behavioral indicators include the immediate prompting for Accessibility Service permission and overlay windows on specific package names (e.g., com.mobilebanking.secure). Network IOCs feature C2 domains ending in .bid, .trade, and .men, with User-Agent strings like "Dalvik/2.1.0 (Linux; U; Android 7.0; SM-G930F)". The malware creates mutex names including "AnubisMutex" and writes persistence files under /data/data/{package}/shared_prefs/ with keys containing "accessibility_prefs".

☠️ Risk & Impact

Anubis causes direct financial losses through credential theft and unauthorized transactions, with ThreatFabric estimating multimillion-dollar damages across the banking and fintech sectors in Europe and the Middle East. It exfiltrates personal identifiable information (PII)—including contacts, call logs, and text messages—and can render devices unusable via ransomware encryption or screen-lock, affecting individual users and corporate mobile devices in industries such as finance, e-commerce, and cryptocurrency exchange operations.

🛡️ Mitigation

Mitigation includes installing applications only from the Google Play Store, disabling the "Install unknown apps" permission, reviewing and revoking Accessibility Service access for apps that do not require it, and deploying mobile threat defense (MTD) solutions like Lookout or Zimperium that detect Anubis behaviour through API hooking and network analysis. Organizations should enforce enterprise mobility management (EMM) policies to block sideloading and ensure regular security patches for Android OS, particularly for vulnerabilities like CVE-2017-8544 that Anubis has historically exploited for privilege escalation.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.