Zanubis is an Android banking trojan first observed in 2022 and primarily focused on victims in Peru. It masquerades as legitimate Peruvian applications and services, including government- and business-themed lures, to trick users into installing it and granting high-risk permissions. The malware is known for abusing Android accessibility services and overlay techniques to monitor victim activity and present fraudulent screens over targeted applications in order to steal credentials. Its targeting has centered on Peruvian banks and financial institutions, and at various stages it also targeted virtual card services and cryptocurrency wallets.
Core Zanubis functionality includes collection of device information, installed application lists, and contact data, followed by communication with command-and-control infrastructure to retrieve configuration data such as targeted application lists. When a victim opens a targeted banking or financial app, Zanubis can display convincing overlay pages to capture login data. Later variants expanded beyond simple overlay theft to include keylogging of user interface events, screen recording, SMS interception and hijacking, and theft of device unlock secrets such as PINs, passwords, and patterns. Some versions also used fake system-update lock screens to obstruct the user while malicious actions were performed in the background.
Zanubis has shown steady development over multiple campaigns. Early variants were comparatively simple and lightly obfuscated, while later versions adopted stronger obfuscation and encrypted command-and-control communications. By 2025, campaigns had incorporated a dropper component that installed the final payload through Android package installation mechanisms, while lure themes shifted to spoof additional Peruvian entities such as an energy company and a bank. Reporting has assessed the operators as likely Peru-based, based on language, targeting, and operational focus. Zanubis remains a persistent regional financial threat aimed at credential theft and broader compromise of Android devices used for banking and related financial services.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware displayed a fake instructional webpage using WebView, claiming that additional permissions were needed to view a document... This trick relies heavily on social engineering... victims are enticed to download the malware under the guise of instructions from a fake bank advisor.
the dropper attempts to silently install the final payload, Zanubis, which is embedded in the initial malware’s internal resources (res/raw/). | The code was fully obfuscated... the threat actors used Obfuscapk... including renaming classes, adding junk code... code RC4 encryption and control-flow obfuscation.
Communication with the C2 API was encrypted with RC4 using a hardcoded key and Base64-encoded... The communication between the C2 and the malware was also protected using AES in ECB mode...
The main infection vector of Zanubis is impersonating legitimate Peruvian Android applications... In April 2023, the malicious package masqueraded as the official Android application of SUNAT... In this new campaign, we have identified two new Peruvian entities being spoofed.
This gave the malware access to verification codes sent by banks and other sensitive services, and even the ability to delete them before the user could see them, effectively hiding its activity.
Whenever the user tries to interact with the targeted application... the malware displays an overlay screen over the targeted application to acquire the log-in credentials of the targeted banking app.
64 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan that impersonates legitimate Peruvian apps, abuses Accessibility permissions, performs overlay attacks, steals banking credentials and device credentials, intercepts SMS for 2FA bypass, enables remote actions, records screens, keylogs input, exfiltrates device data, and can lock devices with fake update screens while operating in the background.
Zanubis is an Android banking trojan targeting financial institutions in Peru, capable of stealing banking credentials, performing remote actions, and harvesting OTPs by impersonating legitimate apps and abusing accessibility permissions.
Android banking trojan that targets financial information and credentials on mobile devices.
Android banking trojan that primarily targets Peruvian banks. It abuses Accessibility Service, requests battery optimization exemptions, hides itself from the app drawer, collects device and contact information, communicates with C2 infrastructure, receives a list of targeted apps, and uses overlay screens to steal banking and government-site credentials.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.