Anubis

Malware family · 1 sample(s) · 3 indicator record(s) · 1 signing certificate(s)

About Anubis

Android banking trojan, a long-lived descendant of the BankBot/Marcher lineage sold as malware-as-a-service. Heavy abuse of accessibility services for overlay credential theft, keylogging and SMS interception, with a ransomware module in later builds. Shipped as a packer: the real payload is an RC4-encrypted asset whose key is an int[] literal in the loader (each element & 0xff); the unpacked config carries the C2 panel and an RC4 key. Many builds use a dead drop - a Twitter/Telegram profile whose text holds the real C2 behind the key - rather than a hardcoded host.

Indicators

IndicatorTypeSampleFirst seen
egxud.com domain 2c4694a79d1b… 2026-10-07
knaver.sayoutube.sldfjl.com domain 2c4694a79d1b… 2026-10-07
198.144.149.130:12380/hello ip 2c4694a79d1b… 2026-10-07