HomeinetAnubisSpy: Steals sensitive data from Android devices

AnubisSpy: Steals sensitive data from Android devices

Android devices appear to be the preferred target of hackers as so far, for 2017, there have been many incidents involving malicious software applications, ransomware and encryption that were designed to infect Android devices. Now, security experts have discovered a new malware for Android named AnubisSpy.

 

AnubisSpy: Steals sensitive data from Android devices

 

The Trend Micro team evaluated seven apps on Google Play and third‑party stores discovering AnubisSpy. These apps were written in Arabic so they are related to Egypt, even mentioned in Egypt’s daily news and Egyptian TV shows. The apps had fake Google certificates and were installed mainly by users in Eastern countries.

AnubisSpy can steal SMS messages, contacts, photos, videos, email accounts, browser histories, screen screenshots, and files from Twitter, Facebook, Skype and WhatsApp. The most interesting thing, however, is that it has a self‑destruct option to hide its traces and delete data on infected devices. The file structure, the decryption method (.JSON), and the C&C servers it uses to manage its entire strategy resemble the operation of Sphinx Malware, which uses the watering‑hole technique to infect users. In the image below you can see its structure.

AnubisSpy Malware

Regarding the date the malicious applications appeared, the researchers stated that they date back to April 2015 and the most recent variant was released in October 2017. Trend Micro contacted Google and asked it to upgrade Google Play Protect in order to prevent the installation of applications that contain AnubisSpy.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS