Anubis
Malware family · 1 sample(s) · 3 indicator record(s) · 1 signing certificate(s)
About Anubis
Android banking trojan, a long-lived descendant of the BankBot/Marcher lineage sold as malware-as-a-service. Heavy abuse of accessibility services for overlay credential theft, keylogging and SMS interception, with a ransomware module in later builds. Shipped as a packer: the real payload is an RC4-encrypted asset whose key is an int[] literal in the loader (each element & 0xff); the unpacked config carries the C2 panel and an RC4 key. Many builds use a dead drop - a Twitter/Telegram profile whose text holds the real C2 behind the key - rather than a hardcoded host.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| egxud.com | domain | 2c4694a79d1b… | 2026-10-07 |
| knaver.sayoutube.sldfjl.com | domain | 2c4694a79d1b… | 2026-10-07 |
| 198.144.149.130:12380/hello | ip | 2c4694a79d1b… | 2026-10-07 |