In its most recent campaigns, FIN7 has been observed deploying the Python-based Anubis backdoor, which provides full system control via in-memory execution and communicates with its command-and-control infrastructure using Base64-encoded data.
Anubis
Anubis is an Android malware family best known as a banking trojan that evolved into a multifunction mobile threat with credential theft, overlay-based phishing, keylogging, SMS abuse, contact theft, audio capture, application and process discovery, and ransomware capabilities.
Profile source: Mallory opens in a new tabAnubis
Family profile
Anubis is an Android malware family best known as a banking trojan that evolved into a multifunction mobile threat with credential theft, overlay-based phishing, keylogging, SMS abuse, contact theft, audio capture, application and process discovery, and ransomware capabilities. It has been observed abusing Android Accessibility Services, including masquerading as Google Play Protect, to obtain elevated interaction privileges that enable credential harvesting, surveillance, and fraud against targeted applications. Anubis can create overlays to capture credentials from banking and other targeted apps, log keystrokes across applications, enumerate installed applications to identify targets, collect running-process information, steal contact lists, send, receive, and delete SMS messages, and record phone calls and ambient audio. It can also exfiltrate files from compromised devices and modify external storage.
Anubis has been distributed through phishing links in email and through trojanized Android applications delivered outside trusted app stores, including fake contact-tracing and coronavirus-themed apps. It has also been associated with dropper campaigns masquerading as legitimate utilities and system components. Reporting has linked Anubis to campaigns targeting banking and cryptocurrency wallet applications at scale, with private variants reportedly aimed at more than a thousand financial and wallet apps. Source-code leaks of Anubis 2.5 contributed to the proliferation of customized variants and influenced later Android banking malware families, including Alien.
In addition to banking-trojan behavior, Anubis includes a ransomware module capable of encrypting device data for extortion and exfiltrating encrypted files. More recent references also associate the Anubis name with a ransomware/extortion operation claiming opportunistic intrusions, rapid victim listing, data theft, and publication of stolen data when demands are not met. Because the name has been used in both Android banking-trojan and ransomware contexts, Anubis should be treated as an overloaded malware name whose meaning depends on operational context. The strongest consistently supported characterization is an Android banking trojan/infostealer family with broad surveillance, credential-theft, and impact capabilities, including mobile ransomware functionality.
Capabilities
- Credential Theft
- Crypto Theft
- Defense Evasion
- Exfiltration
- Keylogging
- Reconnaissance
- Spoofing
Reported operators
Threat actors
1 named in public reportingExploited software
Vulnerabilities linked to Anubis
2 CVEsMITRE ATT&CK
Anubis in ATT&CK
75 distinct techniquesTechniques
75 techniquesReporting
Research mentioning Anubis
500 Hosts, 1 TB and No Negotiation: Anubis Provides Details on the Fairlife Attack - Malware News - Malware Analysis, News and Indicators
The Anubis ransomware group claimed it compromised dairy producer Fairlife, affecting 500 hosts and stealing about 1 TB of data, according to reporting that also highlighted differences between the gang’s account and statements attributed to parent company Coca-Cola. Anubis said the intrusion was opportunistic rather than targeted, describing its method as opening “all doors with weak locks” before determining what it had accessed. Anubis further claimed there was no real negotiation after the intrusion, saying it waited just over a week, attempted to contact the victim by telephone, and then deleted the decryption keys before starting to publish stolen data when no response arrived. The reporting underscores how quickly ransomware operators now move from intrusion to extortion and public leaks, compressing the timeline for incident response, executive decision-making, and disclosure.
500 Hosts, 1 TB and No Negotiation: Anubis Provides Details on the Fairlife Attack - DataBreaches.Net
Операторы вымогателя Anubis взяли на себя ответственность за взлом дочернего предприятия Coca-Cola - Хакер
The Coca-Cola Company disclosed in an SEC filing that a ransomware attack hit systems at its wholly owned dairy subsidiary Fairlife, giving attackers unauthorized access to part of the company’s environment, including production-related systems. The incident forced Fairlife to temporarily suspend production of its products across U.S. facilities, while the company said Canadian operations were not affected and that product quality and safety were not impacted. Coca-Cola said it activated incident response and business continuity procedures, engaged outside advisors and cybersecurity experts, and notified law enforcement as it investigates the full scope and business impact of the breach. The company has not said whether data was stolen, whether an extortion demand was made, or when U.S. production will resume, and no ransomware group had publicly claimed responsibility at the time of reporting.