Anubis Backdoor

First seen
2018-09-01 00:00:00
Malware type
backdoor
Profile updated
2026-07-07 14:39:51

Targeted industries: financial-services retail-and-hospitality

Context

According to Prodaft, this is a Python-based backdoor used by the Savage Ladybug (FIN7) group is developed to provide remote access, execute commands, and steal data. It is obfuscated to avoid detection.

Used by threat actors

  • FIN7 Anubis Backdoor Activity (campaign)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Py.Anubisbackdoor (report)
  • github.com — Anubis%20Backdoor (report)
  • github.com — Anubisbackdoor.Md (report)

External references