Description
Anubis is an Android banking trojan that steals credentials from financial applications and uses overlay attacks to display fake login screens over legitimate ones. It also offers remote access features, keylogging, and ransomware style file locking, and it can intercept SMS messages to bypass text based verification codes. Cyberattackers distribute it through Trojanized applications in third-party stores and phishing links, and its source code has circulated underground, which has produced many variants.
Stats
- First seen
- May 2022
- Last seen
- October 2026
Alert name variants
| Alert Name |
|---|
| Android.Downloader.Anubis |
| Android.Infostealer.Anubis |
| Android.Spyware.Anubis |
| Android.Trojan.Anubis |
| Dump:Generic.Ransom.Anubis.A.8860C99B |
| Trojan.Ransom.Anubis.1 |
| Win64.Infostealer.Anubis |
| Win64.Ransomware.Anubis |
Related IPS Signatures
| Signature Name |
|---|
| MALWARE-OTHER Win.Ransomware.Anubis download attempt |