Anubis Backdoor
- First seen
- 2018-09-01 00:00:00
- Malware type
- backdoor
- Profile updated
- 2026-07-07 14:39:51
Targeted industries: financial-services retail-and-hospitality
Context
According to Prodaft, this is a Python-based backdoor used by the Savage Ladybug (FIN7) group is developed to provide remote access, execute commands, and steal data. It is obfuscated to avoid detection.
Used by threat actors
- FIN7 Anubis Backdoor Activity (campaign)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Py.Anubisbackdoor (report)
- github.com — Anubis%20Backdoor (report)
- github.com — Anubisbackdoor.Md (report)