Skip to content

Malware

Anubis

aka BankBot · android.bankbot · android.bankspy

BleepingComputer found that Anubis will display fake phishing login forms when users open up apps for targeted platforms to steal credentials.

Anubis, also known as BankBot, android.bankbot, android.bankspy, is a Android malware family.

Background

According to BleepingComputer, Anubis steals credentials by popping up counterfeit phishing login forms whenever the victim opens one of the apps it targets. The fraudulent overlay is rendered on top of the genuine app's login screen so that the user believes they are entering data into a legitimate form, while in fact the typed-in credentials are routed to the attackers.

In the variant identified by Lookout, Anubis covers 394 apps and offers the following functionality:

Recording screen activity and audio from the microphone Running a SOCKS5 proxy for covert communication and package delivery Taking screenshots Blasting mass SMS messages from the device to chosen recipients Pulling the device's stored contacts Sending, reading, deleting, and blocking notifications for incoming SMS messages Searching the device for files worth exfiltrating Locking the screen and showing a persistent ransom note Issuing USSD code requests to check bank balances Collecting GPS data and pedometer readings Running a keylogger to capture credentials Watching foreground apps so it can impersonate them and launch overlay attacks Disabling its malicious behavior and uninstalling itself from the device


Source: Malpedia (Fraunhofer FKIE).