Original Release Date: 2017-12-20
Anubis is a mobile malware targeting Android-powered devices, and is delivered via malicious apps that were available on the official Google Play store. The malware is associated with the cyber-espionage group known as "Sphinx" or "APT-C-15." Anubis is used to steal SMS messages, photos, videos, contacts, email accounts, calendar events, and browser histories from Chrome and Samsung Internet Browser. Additionally, it can take screenshots and record audio, including phone calls. It spies on the victims via apps installed on the device, including, but not limited to: Skype, WhatsApp, Facebook, and Twitter. Once the data has been collected, it is encrypted and sent to its C2 server. Anubis can run commands, delete files on the device, install and uninstall APKs, and has the ability to self-destruct.
Technical Details
July 2019: Anubis returns with another variant, recycling similar information-stealing capabilities. (Trend Micro)