Anubis

MITRE ATT&CK: S0422 View on attack.mitre.org

Aliases: Anubis

First seen
2017-01-01 00:00:00
Malware type
trojan
Family
Malware family
Operating systems
android
Related IoCs
57 (26 malicious)
Last IoC activity
2026-08-26 10:35:18
Profile updated
2026-07-07 13:55:58

Targeted industries: financial-services

Targeted regions: country_code:us country_code:de country_code:in country_code:ru

Context

Anubis is Android malware that was originally used for cyber espionage, and has been retooled as a banking trojan.

Recent IoC activity

26 malicious indicators in Maltiverse are attributed to Anubis (S0422). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample b4bd65520d764bea63e2956f63cfe1e79109aa63efc39f3fd938e29df77cf0fd.zip 2026-08-26 1
file sample c7411c0daff520468c3accff4318076a66034b2d14cbae08a5d3ecec2c6ce9ed.zip 2026-08-26 1
file sample b11e45e1f7f4dca9327a10a572c18623.apk 2026-08-24 2
file sample f633b69b4028f9cde42c72b796d3cafb525d935b9ab71a68cc4e74993de7fa03.apk 2026-08-22 2
file sample dde973f01e5116b7482d50559496ff35acff4c043c82f00fcc63d23c621daaad.apk 2026-08-18 2
file sample Anubis_34bec3b2747e.apk 2026-08-16 2
file sample 28c11bb998bf8c023a212c6518b4f8219c8583c2e79fc87d76be6fcad51b522f.apk 2026-08-13 2
file sample b47f2c59b6c4429cf6b4efb050e3ec3d66373dd727ca4215c5f4830cb6bdd792.apk 2026-08-12 2
hostname tryagain.beget.tech 2026-07-21 1
file sample 3f00206aaed4612ce4655152b972aeb2787ca4133aeacc8c9acd8c4d38ea3f79.apk 2026-07-21 2
file sample 0134530694436b0d7f9d0e750191f53fa902425c07af8797d3f82491fef36714.apk 2026-07-21 1
file sample pandemi_basvuru.apk 2026-07-16 1
file sample c38c675a4342052a18e969e839cce797fef842b9d53032882966a3731ced0a70.apk 2026-07-05 2
file sample Hadise_Gizli_Cekim_Ifsa.apk 2026-06-20 2
file sample 0e33a0200df97e40d691d6f57749ac9584652f832c28fd8ad017154b5f9db2b3.apk 2026-06-15 1
file sample 57c9563a1e3adc9737eae84b6fb3f45aa98621ab4d1bced43eeef5e35fee9aad.apk 2026-05-11 1
file sample fcbd91047f1166e7cb77840fcab9a938b5e347373fa1e079939b75c10c5a6437.apk 2026-04-14 1
file sample BASTIAN HEIN MALWARE SAMPLES 3.zip 2026-03-21 1
file sample 2dda951ff826234008eb4dceef73e955.apk 2026-02-25 1
file sample Android_Guncelleme.apk 2026-01-16 1

Malware & tools used

  • Abuse Accessibility Features (attack-pattern)
  • Data from Local System (attack-pattern)
  • Archive Collected Data (attack-pattern)
  • Process Discovery (attack-pattern)
  • System Information Discovery (attack-pattern)
  • SMS Control (attack-pattern)
  • System Checks (attack-pattern)
  • Call Control (attack-pattern)
  • Software Discovery (attack-pattern)
  • GUI Input Capture (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Location Tracking (attack-pattern)
  • Match Legitimate Name or Location (attack-pattern)
  • Contact List (attack-pattern)
  • Screen Capture (attack-pattern)
  • Prevent Application Removal (attack-pattern)
  • Download New Code at Runtime (attack-pattern)
  • Keylogging (attack-pattern)
  • Dead Drop Resolver (attack-pattern)
  • Audio Capture (attack-pattern)

Used by threat actors

  • FIN7 Anubis Backdoor Activity (campaign)

Reports & references

  • ransomlook.io — Anubis (report)
  • bleepingcomputer.com — Anubis Banking Trojan Targets Android Users (report)
  • sentinelone.com — Anubis Android Banking Trojan Analysis (report)
  • Trend Micro — Anubis Malware Family Returns With New Variants (report)
  • blog.cyble.com — Anubis Banking Trojan Targets Multiple Countries (report)
  • CISA — Ar22 187A (report)
  • MITRE ATT&CK — S0422 (report)
  • web.archive.org — Infostealer Keylogger Ransomware One Anubis Targets 250 Android Applications (report)

External references