Trojan

Anubis

First seen: 2017-01 • Status: active

Currently Active Threat

Anubis is an Android banking virus that shows fake login screens over your real banking app to steal your passwords and money.

Overview

Anubis is an Android banking trojan that has been active since 2017. It targets hundreds of banking apps worldwide using overlay attacks.

Also Known As

Anubis Banker, BankBot Anubis

How It Spreads

  • Google Play malicious apps
  • Phishing
  • Fake app stores

What It Does

  • Overlay attacks on banking apps
  • Keylogging
  • Screen recording
  • SMS interception

Is your business exposed?

Target Platforms

Android

Detection Tips

  • Check accessibility service usage
  • Monitor for overlay permissions

MITRE ATT&CK Techniques

T1417, T1411, T1056

If You're Infected

  1. 1.

    Uninstall suspicious apps

  2. 2.

    Contact bank if credentials entered

Related Malware

Cerberus, Spynote

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required