Anubis is an overloaded malware name used for two distinct threat clusters: an Android banking trojan and an emerging ransomware-as-a-service operation. The Android Anubis trojan has been distributed through phishing links and trojanized applications, including COVID-19-themed contact-tracing lures. It masquerades as legitimate Android security or system-update software, requests Accessibility Service privileges, and targets banking applications with credential-harvesting overlays. Its documented capabilities include cross-application keylogging, SMS interception and manipulation, contact theft, installed-application and process discovery, audio and call recording, and collection or exfiltration of device files. It can also encrypt device data for ransom.
The separate Anubis ransomware operation emerged in 2025 and operates an affiliate model offering encryption, data-extortion, and access-monetization arrangements. It is assessed to use spearphishing for initial access and performs privilege checks or elevation, shadow-copy deletion, service and process disruption, ECIES-based file encryption, and data-leak extortion. An optional wiping mode permanently clears file contents to inhibit recovery, creating a destructive impact beyond conventional encryption. Reported victims include organizations in healthcare, engineering, and construction in Australia, Canada, Peru, and the United States. Storm-2570 has deployed Anubis ransomware alongside other ransomware payloads in intrusions involving credential theft, remote-management tooling, lateral movement, security-control tampering, and cloud-based data exfiltration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Resecurity tied the group to mass exploitation of internet-facing systems, often via known but unpatched flaws, including: ... SolarWinds Web Help Desk (CVE-2025-26399) ... | An attack by the Anubis ransomware group on a port authority on the Adriatic has been cast as a warning to maritime infrastructure... The Anubis Affiliate Machine Anubis surfaced in December 2024 and launched an affiliate program in February 2025, renting out its toolkit through a ransomware-as-a-service (RaaS) model built around double extortion.
Resecurity tied the group to mass exploitation of internet-facing systems, often via known but unpatched flaws, including: ... The CitrixBleed 2 flaw (CVE-2025-5777) | An attack by the Anubis ransomware group on a port authority on the Adriatic has been cast as a warning to maritime infrastructure... The Anubis Affiliate Machine Anubis surfaced in December 2024 and launched an affiliate program in February 2025, renting out its toolkit through a ransomware-as-a-service (RaaS) model built around double extortion.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Storm-2570 defense-evasion tactics were observed across ransomware intrusions involving Qilin, DragonForce, and Anubis deployment.
In its most recent campaigns, FIN7 has been observed deploying the Python-based Anubis backdoor, which provides full system control via in-memory execution and communicates with its command-and-control infrastructure using Base64-encoded data.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK ID Description T1047 Windows Management Instrumentation
After decoding base64, it uses service to decrypt data that encrypted with rc4 scheme... Here is output of my script to get c2 and key from an Anubis sample.
MITRE ATT&CK ID Description T1059.001 Command and Scripting Interpreter: PowerShell
MITRE ATT&CK ID Description T1059.003 Command and Scripting Interpreter: Windows Command Shell
Once executed, the XLL payload initiates a series of code injection techniques... as one of the security vendors started flagging rundll32-based executions generically, the group was forced to experiment with process injection and alternative staging mechanisms.
A malicious application could create an application overlay window on top of a running legitimate application.
At a first look, it seemed clear that the APK was heavily obfuscated... It seems to mostly rely on generating a variety of random functions to hide the real functionalities of the sample... Most of the strings in the code are generated by using functions implementing a XOR decryption of byte arrays.
The source code also appears to have been merged into one main file with most of the function names being obfuscated, as opposed to the previously separated but clear functionality.
Agent Smith can impersonate any popular application on an infected device, and the core malware disguises itself as a legitimate Google application.
Once executed, the XLL payload initiates a series of code injection techniques... as one of the security vendors started flagging rundll32-based executions generically, the group was forced to experiment with process injection and alternative staging mechanisms.
After loading with DexClassLoader, malware removes the decrypted dex file.
“The Overlay attack is a well-known technique implemented on modern Android banking trojans... This usually takes the form of an imitation app or a WebView launched ‘on-top’ of a legitimate application (such as a banking app).”
Malicious functionality in these trojanized contact-tracing applications includes: ... Keylogging ...
Intercepting, redirecting, sending and deleting SMS messages, to bypass SMS-based 2-factor authentication
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
“The Overlay attack is a well-known technique implemented on modern Android banking trojans... This usually takes the form of an imitation app or a WebView launched ‘on-top’ of a legitimate application (such as a banking app).”
Malicious functionality in these trojanized contact-tracing applications includes: ... Keylogging ...
Malicious functionality in these trojanized contact-tracing applications includes: ... Voice, Screen, and Camera recording and exfiltration
another trove of data was found within the clipboard synchronization feature. By copy/pasting between victim and attacker machines, operators exposed some additional TTPs and information surrounding their operations.
Malicious functionality in these trojanized contact-tracing applications includes: ... Voice, Screen, and Camera recording and exfiltration
this malware uses social media to obtain its C2: it downloads the webpage of a photo-less Instagram account. It then extracts the biography field of this account and decodes it using Base64.
Sitnikov was allegedly charged for posting the source code of the Anubis banking trojan on Freedom F0x
77 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
105 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware payload deployed by Storm-2570; activity preceding deployment includes Microsoft Defender tampering and data theft.
Ransomware-as-a-service that encrypts files with an ECIES-based implementation, appends the .anubis extension, deletes shadow copies, stops services, and uses double extortion. Its /WIPEMODE capability overwrites file contents, leaving files at 0 KB and preventing recovery even after encryption.
Ransomware associated in the article with the alleged compromise of Fairlife and theft of over 1 TB of data.
Referenced explicitly as an Android banking trojan sample the poster tried to obtain/test.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.