Skip to content

Anubis

Anubis is an Android banking trojan associated with credential theft, financial fraud, and device surveillance.

Profile source: Mallory opens in a new tab

Anubis

Family profile

Anubis is an Android banking trojan associated with credential theft, financial fraud, and device surveillance. It targets banking and cryptocurrency-wallet applications by enumerating installed apps and running processes, then deploying credential-harvesting overlays over selected applications. It can abuse Android Accessibility Services while masquerading as a trusted security component, enabling it to capture keystrokes across applications and support interaction with victim devices. Anubis can collect contacts, record microphone audio and telephone calls, send, receive, and delete SMS messages, and collect or exfiltrate files from device storage. Some variants include a ransomware module capable of encrypting device data and extorting victims. Campaigns have distributed Anubis through phishing links, trojanized and fake applications, including COVID-19-themed contact-tracing applications, and dropper applications masquerading as legitimate utilities. Private variants have been used in campaigns targeting banking and cryptocurrency-wallet users, including large-scale distribution through deceptive Android applications.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Reconnaissance

Operational record

30
Indicators
1
YARA rules
1
Ransom notes
2
Leak sites
2 available

Published indicators

Twitter

1 total
  • @Anubis__media

Md5

25 total
  • a1765503f1405b24b77a16071e6ea6f6
  • d2410703e93be61a652b92efcf42789d
  • 0a5f3fc92af7aa3e448ac7b84e495fc6
  • 271998018494403a9b5d0d4b01eb0c44
  • 8a12e997e672b80319c5b852b237e5a9
  • f71d8db7fda7659718330efcbd0776f0
  • 0f1b8aa83e5f9c40ad32561a95ed2c67
  • 71ce395e8bb531ec3623b94387de8392
  • 284d536dab5865150873e927a29cb0ae
  • a4b88bf440613390cd32e045a59fd7b0

Ip

4 total
  • 38.134.148.20
  • 5.252.177.249
  • 212.224.107.203
  • 195.133.67.35

Recent claims

Reported operators

Threat actors

1 named in public reporting
FIN7

In its most recent campaigns, FIN7 has been observed deploying the Python-based Anubis backdoor, which provides full system control via in-memory execution and communicates with its command-and-control infrastructure using Base64-encoded data.

Exploited software

Vulnerabilities linked to Anubis

2 CVEs

MITRE ATT&CK

Anubis in ATT&CK

75 distinct techniques

Techniques

75 techniques
T1005 Data from Local System T1041 Exfiltration Over C2 Channel T1546 Event Triggered Execution T1123 Audio Capture T1056.001 Keylogging T1036 Masquerading T1125 Video Capture T1548 Abuse Elevation Control Mechanism T1113 Screen Capture T1059.001 PowerShell T1033 System Owner/User Discovery T1547.001 Registry Run Keys / Startup Folder T1571 Non-Standard Port T1047 Windows Management Instrumentation T1082 System Information Discovery T1027 Obfuscated Files or Information T1027.002 Software Packing T1132.001 Standard Encoding T1059.003 Windows Command Shell T1111 Multi-Factor Authentication Interception T1528 Steal Application Access Token T1055 Process Injection T1566 Phishing T1056 Input Capture T1102 Web Service T1140 Deobfuscate/Decode Files or Information T1587.001 Malware T1204.002 Malicious File T1649 Steal or Forge Authentication Certificates T1213 Data from Information Repositories T1059 Command and Scripting Interpreter T1105 Ingress Tool Transfer T1129 Shared Modules T1620 Reflective Code Loading T1070.004 File Deletion T1115 Clipboard Data T1018 Remote System Discovery T1021.002 SMB/Windows Admin Shares T1219 Remote Access Tools T1083 File and Directory Discovery T1071 Application Layer Protocol T1665 Hide Infrastructure T1114 Email Collection T1016 System Network Configuration Discovery T1057 Process Discovery T1204 User Execution T1497 Virtualization/Sandbox Evasion T1546.008 Accessibility Features T1074 Data Staged T1567 Exfiltration Over Web Service T1486 Data Encrypted for Impact T1561.001 Disk Content Wipe T1537 Transfer Data to Cloud Account T1561 Disk Wipe T1657 Financial Theft T1218 System Binary Proxy Execution T1190 Exploit Public-Facing Application T1133 External Remote Services T1090 Proxy T1567.002 Exfiltration to Cloud Storage T1490 Inhibit System Recovery T1021.001 Remote Desktop Protocol T1021 Remote Services T1078 Valid Accounts T1572 Protocol Tunneling T1562 Impair Defenses T1569.002 Service Execution T1485 Data Destruction T1056.004 Credential API Hooking T1218.011 Rundll32 T1566.002 Spearphishing Link T1566.001 Spearphishing Attachment T1555 Credentials from Password Stores T1071.001 Web Protocols T1189 Drive-by Compromise

Reporting

Research mentioning Anubis

Aug 26
Zdnet Zero Day

July was the worst month for ransomware victim claims in 2026 - or was it? | ZDNET

Security reporting has documented LameHug as the first publicly known malware to integrate a large language model, marking an escalation in the use of generative AI within malicious tooling. The development indicates that AI can be incorporated into malware operations rather than being used solely to create phishing content or assist attackers outside the payload. Separately, ransomware victim listings reached 894 organizations in July 2026, according to NCC Group data cited by ZDNET, with industrial organizations comprising nearly one-third of listed victims. The reporting also identified the first documented fully agentic AI ransomware attack chain, attributed to JadePuffer, amid a surge led by groups including The Gentlemen and Qilin; however, organizations should treat leak-site claims cautiously because some actors, including the new CRPxO RaaS operation, may inflate or fabricate victim listings.

Aug 16
Malware News

500 Hosts, 1 TB and No Negotiation: Anubis Provides Details on the Fairlife Attack - Malware News - Malware Analysis, News and Indicators

The Anubis ransomware group claimed it compromised dairy producer Fairlife, affecting 500 hosts and stealing about 1 TB of data, according to reporting that also highlighted differences between the gang’s account and statements attributed to parent company Coca-Cola. Anubis said the intrusion was opportunistic rather than targeted, describing its method as opening “all doors with weak locks” before determining what it had accessed. Anubis further claimed there was no real negotiation after the intrusion, saying it waited just over a week, attempted to contact the victim by telephone, and then deleted the decryption keys before starting to publish stolen data when no response arrived. The reporting underscores how quickly ransomware operators now move from intrusion to extortion and public leaks, compressing the timeline for incident response, executive decision-making, and disclosure.

Aug 16
Data Breaches

500 Hosts, 1 TB and No Negotiation: Anubis Provides Details on the Fairlife Attack - DataBreaches.Net

Jul 23
Xakep

Операторы вымогателя Anubis взяли на себя ответственность за взлом дочернего предприятия Coca-Cola - Хакер

The Coca-Cola Company disclosed in an SEC filing that a ransomware attack hit systems at its wholly owned dairy subsidiary Fairlife, giving attackers unauthorized access to part of the company’s environment, including production-related systems. The incident forced Fairlife to temporarily suspend production of its products across U.S. facilities, while the company said Canadian operations were not affected and that product quality and safety were not impacted. Coca-Cola said it activated incident response and business continuity procedures, engaged outside advisors and cybersecurity experts, and notified law enforcement as it investigates the full scope and business impact of the breach. The company has not said whether data was stolen, whether an extortion demand was made, or when U.S. production will resume, and no ransomware group had publicly claimed responsibility at the time of reporting.

Jul 22
Security Week

Ransomware Group Threatening to Leak Data Stolen From Coca-Cola's Fairlife - SecurityWeek

Jul 22
Cyberthrone

Coca-Cola Fairlife Ransomware Attack - TheCyberThrone

Jul 22
Teiss News

teiss - News - Anubis ransomware gang claims Coca-Cola's Fairlife in data extortion threat

Jul 21
Bleeping Computer

Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.