Anubis (Android)
Aliases: BankBot, android.bankbot, android.bankspy
- First seen
- 2017-07-01 00:00:00
- Malware type
- credential-stealer, keylogger, ransomware, spyware, trojan
- Family
- Malware family
- Last IoC activity
- 2026-07-21 22:26:26
- Profile updated
- 2026-07-07 13:46:55
Targeted industries: financial-services retail-and-hospitality
Context
BleepingComputer found that Anubis will display fake phishing login forms when users open up apps for targeted platforms to steal credentials. This overlay screen will be shown over the real app's login screen to make victims think it's a legitimate login form when in reality, inputted credentials are sent to the attackers. In the new version spotted by Lookout, Anubis now targets 394 apps and has the following capabilities: Recording screen activity and sound from the microphone Implementing a SOCKS5 proxy for covert communication and package delivery Capturing screenshots Sending mass SMS messages from the device to specified recipients Retrieving contacts stored on the device Sending, reading, deleting, and blocking notifications for SMS messages received by the device Scanning the device for files of interest to exfiltrate Locking the device screen and displaying a persistent ransom note Submitting USSD code requests to query bank balances Capturing GPS data and pedometer statistics Implementing a keylogger to steal credentials Monitoring active apps to mimic and perform overlay attacks Stopping malicious functionality and removing the malware from the device
Reports & references
- assets.virustotal.com — 2021Trends (report)
- threatfabric.com — The Rage Of Android Banking Trojans (report)
- cocomelonc.github.io — Aiya Mmd Book (report)
- malpedia.caad.fkie.fraunhofer.de — Apk.Anubis (report)
- blog.koodous.com — Decrypting Bankbot Communications (report)
- threatfabric.com — 2020 Year Of The Rat (report)
- Trend Micro — Google Play Apps Drop Anubis Banking Malware Use Motion Based Evasion Tactics (report)
- intel-honey.medium.com — Reversing Anubis Malware 93F28D154Bbb (report)
- bushidotoken.blogspot.com — Turkey Targeted By Cerberus And Anubis (report)
- ESET — New Campaigns Spread Banking Malware Google Play (report)
- pentest.blog — N Ways To Unpack Mobile Malware (report)
- 0x1c3n.tech — Anubis Android Malware Analysis (report)
- info.phishlabs.com — New Variant Bankbot Banking Trojan Aubis (report)
- securityboulevard.com — Android Malware Intercepts Sms 2Fa We Have The Logs (report)
- Kaspersky — 96280 (report)
- sysopfb.github.io — Unpacking Anubis Apk (report)
- eybisi.run — Mobile Malware Analysis Tricks Used In Anubis (report)
- n1ght-w0lf.github.io — Anubis Banking Malware (report)
- blog.koodous.com — Bankbot On Google Play (report)
- fortinet.com — A Look Into The New Strain Of Bankbot (report)
- muha2xmad.github.io — Anubis (report)
- fortinet.com — Bankbot The Prequel (report)
- securityboulevard.com (report)
- securityaffairs.co — Anubis Networks New C2 (report)
- securityintelligence.com — After Big Takedown Efforts 20 More Bankbot Mobile Malware Apps Make It Into Google Play (report)