Two Android apps published on Google Play, Currency Converter and BatterySaverMobi, were found to function as droppers for the Anubis banking trojan. The apps used motion-sensor checks to detect whether they were running on a real device rather than in a sandbox or emulator, then fetched command-and-control details through encoded requests tied to Telegram and Twitter pages. After installation, they displayed a fake system update prompt designed to persuade users to sideload a malicious APK that delivered the Anubis payload.
Once deployed, Anubis was capable of targeting 377 financial app variants across 93 countries and stealing data through keylogging, screenshots, abuse of Android accessibility features, and broad device permissions. Researchers linked the activity to infrastructure including the domain aserogeege.space, and Google removed both malicious apps from the Play Store after the discovery.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
After the apps were discovered, Google removed Currency Converter and BatterySaverMobi from the Play Store. The apps were linked to Anubis infrastructure including the domain aserogeege.space, and the malware was described as targeting 377 financial app variants across 93 countries.
Researchers identified two Android apps on Google Play, Currency Converter and BatterySaverMobi, that acted as droppers for the Anubis banking malware. The apps used motion-sensor-based anti-analysis checks, fetched command-and-control details via encoded Telegram and Twitter requests, and tried to trick users into installing a fake system update APK.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.