Skip to main content

AnubisSpy Android Malware

AnubisSpy is a mobile trojan that can steal messages (SMS), photos, videos, contacts, email accounts, calendar events, and browser histories, and take screenshots and record audio, including calls.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

AnubisSpy is a mobile trojan that can steal messages (SMS), photos, videos, contacts, email accounts, calendar events, and browser histories, and take screenshots and record audio, including calls.

Affected platforms

The following platforms are known to be affected:

Threat details

It can spy on the user through apps installed on the device, a list of which is in its configuration file that can be updated. This includes Skype, WhatsApp, Facebook, and Twitter, among others.After the data is collected, it is encrypted and sent to the Command and Control (C2) server. AnubisSpy can also self-destruct to cover its tracks. It can run commands and delete files on the device, as well as install and uninstall Android Application Packages (APKs).

Remediation steps

Type Step
  • Users should always download apps from the official stores - infected programs are usually distributed from third-party sites not affiliated with Google Play.
  • The Android device security software should be kept up-to-date.
  • User should be vigilant of unsolicited email links and attachments.
  • Review the permissions the application will request

Last edited: 17 February 2020 12:37 pm