Anubis Backdoor is a Python-based backdoor associated with the Savage Ladybug threat group, also tracked as FIN7. It is designed to provide remote access to compromised systems, execute attacker-supplied commands, and steal data. Reported implementations use obfuscation extensively to hinder analysis and evade detection, including decoy code structures, confusing identifier naming, and layered concealment that separates nonfunctional code from the operational backdoor logic. The functional component includes network communications, command handling, and system manipulation capabilities consistent with a remote-access backdoor used in post-compromise operations. This malware is distinct from the unrelated Anubis ransomware operation and other malware families that share the same name.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Anubis Backdoor A Python-based backdoor used by the Savage Ladybug (FIN7) group is developed to provide remote access, execute commands, and steal data. It is obfuscated to avoid detection.
Anubis Backdoor A Python-based backdoor used by the Savage Ladybug (FIN7) group is developed to provide remote access, execute commands, and steal data. It is obfuscated to avoid detection.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor historically associated with FIN7, referenced only to clarify it is not related to Anubis ransomware (name overlap only).
A backdoor payload (stage 2) that is heavily obfuscated using decoy class structures and visually confusing identifier naming, and implements network communications, command handling, and system manipulation capabilities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.