Netskope Threat Labs

Anubis

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Anubis is an Android banking trojan that steals credentials from financial applications and uses overlay attacks to display fake login screens over legitimate ones. It also offers remote access features, keylogging, and ransomware style file locking, and it can intercept SMS messages to bypass text based verification codes. Cyberattackers distribute it through Trojanized applications in third-party stores and phishing links, and its source code has circulated underground, which has produced many variants.

First seen
May 2022
Last seen
October 2026
Alert Name
Android.Downloader.Anubis
Android.Infostealer.Anubis
Android.Spyware.Anubis
Android.Trojan.Anubis
Dump:Generic.Ransom.Anubis.A.8860C99B
Trojan.Ransom.Anubis.1
Win64.Infostealer.Anubis
Win64.Ransomware.Anubis