@Anubis__media
Anubis
Anubis is an Android banking trojan associated with credential theft, financial fraud, and device surveillance.
Profile source: Mallory opens in a new tabAnubis
Family profile
Anubis is an Android banking trojan associated with credential theft, financial fraud, and device surveillance. It targets banking and cryptocurrency-wallet applications by enumerating installed apps and running processes, then deploying credential-harvesting overlays over selected applications. It can abuse Android Accessibility Services while masquerading as a trusted security component, enabling it to capture keystrokes across applications and support interaction with victim devices. Anubis can collect contacts, record microphone audio and telephone calls, send, receive, and delete SMS messages, and collect or exfiltrate files from device storage. Some variants include a ransomware module capable of encrypting device data and extorting victims. Campaigns have distributed Anubis through phishing links, trojanized and fake applications, including COVID-19-themed contact-tracing applications, and dropper applications masquerading as legitimate utilities. Private variants have been used in campaigns targeting banking and cryptocurrency-wallet users, including large-scale distribution through deceptive Android applications.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Keylogging
- Reconnaissance
Operational record
Published indicators
Md5
25 totala1765503f1405b24b77a16071e6ea6f6d2410703e93be61a652b92efcf42789d0a5f3fc92af7aa3e448ac7b84e495fc6271998018494403a9b5d0d4b01eb0c448a12e997e672b80319c5b852b237e5a9f71d8db7fda7659718330efcbd0776f00f1b8aa83e5f9c40ad32561a95ed2c6771ce395e8bb531ec3623b94387de8392284d536dab5865150873e927a29cb0aea4b88bf440613390cd32e045a59fd7b0
Ip
4 total38.134.148.205.252.177.249212.224.107.203195.133.67.35
Recent claims
Reported operators
Threat actors
1 named in public reportingIn its most recent campaigns, FIN7 has been observed deploying the Python-based Anubis backdoor, which provides full system control via in-memory execution and communicates with its command-and-control infrastructure using Base64-encoded data.
Exploited software
Vulnerabilities linked to Anubis
2 CVEsMITRE ATT&CK
Anubis in ATT&CK
75 distinct techniquesTechniques
75 techniquesReporting
Research mentioning Anubis
July was the worst month for ransomware victim claims in 2026 - or was it? | ZDNET
Security reporting has documented LameHug as the first publicly known malware to integrate a large language model, marking an escalation in the use of generative AI within malicious tooling. The development indicates that AI can be incorporated into malware operations rather than being used solely to create phishing content or assist attackers outside the payload. Separately, ransomware victim listings reached 894 organizations in July 2026, according to NCC Group data cited by ZDNET, with industrial organizations comprising nearly one-third of listed victims. The reporting also identified the first documented fully agentic AI ransomware attack chain, attributed to JadePuffer, amid a surge led by groups including The Gentlemen and Qilin; however, organizations should treat leak-site claims cautiously because some actors, including the new CRPxO RaaS operation, may inflate or fabricate victim listings.
500 Hosts, 1 TB and No Negotiation: Anubis Provides Details on the Fairlife Attack - Malware News - Malware Analysis, News and Indicators
The Anubis ransomware group claimed it compromised dairy producer Fairlife, affecting 500 hosts and stealing about 1 TB of data, according to reporting that also highlighted differences between the gang’s account and statements attributed to parent company Coca-Cola. Anubis said the intrusion was opportunistic rather than targeted, describing its method as opening “all doors with weak locks” before determining what it had accessed. Anubis further claimed there was no real negotiation after the intrusion, saying it waited just over a week, attempted to contact the victim by telephone, and then deleted the decryption keys before starting to publish stolen data when no response arrived. The reporting underscores how quickly ransomware operators now move from intrusion to extortion and public leaks, compressing the timeline for incident response, executive decision-making, and disclosure.
500 Hosts, 1 TB and No Negotiation: Anubis Provides Details on the Fairlife Attack - DataBreaches.Net
Операторы вымогателя Anubis взяли на себя ответственность за взлом дочернего предприятия Coca-Cola - Хакер
The Coca-Cola Company disclosed in an SEC filing that a ransomware attack hit systems at its wholly owned dairy subsidiary Fairlife, giving attackers unauthorized access to part of the company’s environment, including production-related systems. The incident forced Fairlife to temporarily suspend production of its products across U.S. facilities, while the company said Canadian operations were not affected and that product quality and safety were not impacted. Coca-Cola said it activated incident response and business continuity procedures, engaged outside advisors and cybersecurity experts, and notified law enforcement as it investigates the full scope and business impact of the breach. The company has not said whether data was stolen, whether an extortion demand was made, or when U.S. production will resume, and no ransomware group had publicly claimed responsibility at the time of reporting.