Two Android apps on Google Play, Currency Converter and BatterySaverMobi, were found distributing the Anubis banking trojan through a dropper chain that prompted users to install a fake system update. The malware used motion-sensor checks to evade sandboxes and emulators, pulled command-and-control details from Telegram and Twitter content, and was linked to infrastructure including the domain aserogeege.space and IP address 47.254.26.2. Once installed, Anubis targeted banking users across 93 countries and 377 financial app variants, stealing credentials through keylogging and screenshots while also abusing accessibility services to access contacts, location, audio, SMS, calls, and storage.
Technical analysis showed the Anubis payload was heavily protected with reflection, obfuscation, runtime class loading, and encrypted .dex files, complicating static inspection. Researchers demonstrated that dynamic instrumentation with Frida could trace reflection calls, intercept file deletion, and preserve decrypted payloads dropped at runtime, while alternative methods recovered .dex remnants from memory or extracted the RC4 key and C2 configuration directly from the APK. Google removed the malicious apps from the Play Store after the abuse was confirmed, but the case highlighted how mobile banking malware can combine trusted distribution channels, anti-analysis tricks, and layered packing to hinder detection and reverse engineering.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Pentest Blog released a technical walkthrough showing how to unpack Anubis by tracing reflection with Frida, intercepting file deletion, recovering decrypted dex files, and extracting RC4 keys and command-and-control data. The article documented both dynamic and static approaches for recovering the malware payload and configuration.
Trend Micro disclosed that the droppers recovered command-and-control information from Telegram and Twitter pages, connected to the domain aserogeege.space, and deployed an Anubis payload capable of keylogging, screenshots, accessibility abuse, and broader device access. The report also said the latest Anubis version had spread across 93 countries and targeted 377 financial app variants.
Trend Micro reported that malicious domains tied to Anubis infrastructure may have switched IP addresses six times since October 2018, indicating active infrastructure rotation. The domains were associated with the IP address 47.254.26.2 and related command-and-control activity.
Pentest Blog stated that in the prior fall there were at least forty Google Play cases involving Anubis droppers targeting Turkish users. These apps used generic names and served as distribution vehicles for the banking malware.
After confirmation of abuse, Google removed the malicious apps Currency Converter and BatterySaverMobi from Google Play. One of the apps, BatterySaverMobi, had accumulated more than 5,000 downloads before removal.
Trend Micro discovered that the Android apps Currency Converter and BatterySaverMobi on Google Play were acting as droppers for the Anubis banking malware. The apps used motion-sensor-based anti-analysis checks and attempted to trick users into installing a secondary APK via a fake system update.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
pentest.blog
Open sourceblog.trendmicro.com
Open sourcefrida.re
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.