Skip to content

Anubis

Anubis is an Android malware family best known as a banking trojan that evolved into a multifunction mobile threat with credential theft, overlay-based phishing, keylogging, SMS abuse, contact theft, audio capture, application and process discovery, and ransomware capabilities.

Profile source: Mallory opens in a new tab

Anubis

Family profile

Anubis is an Android malware family best known as a banking trojan that evolved into a multifunction mobile threat with credential theft, overlay-based phishing, keylogging, SMS abuse, contact theft, audio capture, application and process discovery, and ransomware capabilities. It has been observed abusing Android Accessibility Services, including masquerading as Google Play Protect, to obtain elevated interaction privileges that enable credential harvesting, surveillance, and fraud against targeted applications. Anubis can create overlays to capture credentials from banking and other targeted apps, log keystrokes across applications, enumerate installed applications to identify targets, collect running-process information, steal contact lists, send, receive, and delete SMS messages, and record phone calls and ambient audio. It can also exfiltrate files from compromised devices and modify external storage.

Anubis has been distributed through phishing links in email and through trojanized Android applications delivered outside trusted app stores, including fake contact-tracing and coronavirus-themed apps. It has also been associated with dropper campaigns masquerading as legitimate utilities and system components. Reporting has linked Anubis to campaigns targeting banking and cryptocurrency wallet applications at scale, with private variants reportedly aimed at more than a thousand financial and wallet apps. Source-code leaks of Anubis 2.5 contributed to the proliferation of customized variants and influenced later Android banking malware families, including Alien.

In addition to banking-trojan behavior, Anubis includes a ransomware module capable of encrypting device data for extortion and exfiltrating encrypted files. More recent references also associate the Anubis name with a ransomware/extortion operation claiming opportunistic intrusions, rapid victim listing, data theft, and publication of stolen data when demands are not met. Because the name has been used in both Android banking-trojan and ransomware contexts, Anubis should be treated as an overloaded malware name whose meaning depends on operational context. The strongest consistently supported characterization is an Android banking trojan/infostealer family with broad surveillance, credential-theft, and impact capabilities, including mobile ransomware functionality.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Reconnaissance
  • Spoofing

Reported operators

Threat actors

1 named in public reporting
FIN7

In its most recent campaigns, FIN7 has been observed deploying the Python-based Anubis backdoor, which provides full system control via in-memory execution and communicates with its command-and-control infrastructure using Base64-encoded data.

Exploited software

Vulnerabilities linked to Anubis

2 CVEs

MITRE ATT&CK

Anubis in ATT&CK

75 distinct techniques

Techniques

75 techniques
T1005 Data from Local System T1041 Exfiltration Over C2 Channel T1546 Event Triggered Execution T1123 Audio Capture T1056.001 Keylogging T1036 Masquerading T1125 Video Capture T1548 Abuse Elevation Control Mechanism T1113 Screen Capture T1059.001 PowerShell T1033 System Owner/User Discovery T1547.001 Registry Run Keys / Startup Folder T1571 Non-Standard Port T1047 Windows Management Instrumentation T1082 System Information Discovery T1027 Obfuscated Files or Information T1027.002 Software Packing T1132.001 Standard Encoding T1059.003 Windows Command Shell T1111 Multi-Factor Authentication Interception T1528 Steal Application Access Token T1055 Process Injection T1566 Phishing T1056 Input Capture T1102 Web Service T1140 Deobfuscate/Decode Files or Information T1587.001 Malware T1204.002 Malicious File T1649 Steal or Forge Authentication Certificates T1213 Data from Information Repositories T1059 Command and Scripting Interpreter T1105 Ingress Tool Transfer T1129 Shared Modules T1620 Reflective Code Loading T1070.004 File Deletion T1115 Clipboard Data T1018 Remote System Discovery T1021.002 SMB/Windows Admin Shares T1219 Remote Access Tools T1083 File and Directory Discovery T1071 Application Layer Protocol T1665 Hide Infrastructure T1114 Email Collection T1016 System Network Configuration Discovery T1057 Process Discovery T1204 User Execution T1497 Virtualization/Sandbox Evasion T1546.008 Accessibility Features T1074 Data Staged T1567 Exfiltration Over Web Service T1486 Data Encrypted for Impact T1561.001 Disk Content Wipe T1537 Transfer Data to Cloud Account T1561 Disk Wipe T1657 Financial Theft T1218 System Binary Proxy Execution T1190 Exploit Public-Facing Application T1133 External Remote Services T1090 Proxy T1567.002 Exfiltration to Cloud Storage T1490 Inhibit System Recovery T1021.001 Remote Desktop Protocol T1021 Remote Services T1078 Valid Accounts T1572 Protocol Tunneling T1562 Impair Defenses T1569.002 Service Execution T1485 Data Destruction T1056.004 Credential API Hooking T1218.011 Rundll32 T1566.002 Spearphishing Link T1566.001 Spearphishing Attachment T1555 Credentials from Password Stores T1071.001 Web Protocols T1189 Drive-by Compromise

Reporting

Research mentioning Anubis

Aug 16
Malware News

500 Hosts, 1 TB and No Negotiation: Anubis Provides Details on the Fairlife Attack - Malware News - Malware Analysis, News and Indicators

The Anubis ransomware group claimed it compromised dairy producer Fairlife, affecting 500 hosts and stealing about 1 TB of data, according to reporting that also highlighted differences between the gang’s account and statements attributed to parent company Coca-Cola. Anubis said the intrusion was opportunistic rather than targeted, describing its method as opening “all doors with weak locks” before determining what it had accessed. Anubis further claimed there was no real negotiation after the intrusion, saying it waited just over a week, attempted to contact the victim by telephone, and then deleted the decryption keys before starting to publish stolen data when no response arrived. The reporting underscores how quickly ransomware operators now move from intrusion to extortion and public leaks, compressing the timeline for incident response, executive decision-making, and disclosure.

Aug 16
Data Breaches

500 Hosts, 1 TB and No Negotiation: Anubis Provides Details on the Fairlife Attack - DataBreaches.Net

Jul 23
Xakep

Операторы вымогателя Anubis взяли на себя ответственность за взлом дочернего предприятия Coca-Cola - Хакер

The Coca-Cola Company disclosed in an SEC filing that a ransomware attack hit systems at its wholly owned dairy subsidiary Fairlife, giving attackers unauthorized access to part of the company’s environment, including production-related systems. The incident forced Fairlife to temporarily suspend production of its products across U.S. facilities, while the company said Canadian operations were not affected and that product quality and safety were not impacted. Coca-Cola said it activated incident response and business continuity procedures, engaged outside advisors and cybersecurity experts, and notified law enforcement as it investigates the full scope and business impact of the breach. The company has not said whether data was stolen, whether an extortion demand was made, or when U.S. production will resume, and no ransomware group had publicly claimed responsibility at the time of reporting.

Jul 22
Security Week

Ransomware Group Threatening to Leak Data Stolen From Coca-Cola's Fairlife - SecurityWeek

Jul 22
Cyberthrone

Coca-Cola Fairlife Ransomware Attack - TheCyberThrone

Jul 22
Teiss News

teiss - News - Anubis ransomware gang claims Coca-Cola's Fairlife in data extortion threat

Jul 21
Bleeping Computer

Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak

Jul 21
Securitymagazine

Cyberattack Halts Coca-Cola's Fairlife Productions | Security Magazine

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.