Android devices appear to be the preferred target of hackers as so far, for 2017, there have been many incidents involving malicious software applications, ransomware and encryption that were designed to infect Android devices. Now, security experts have discovered a new malware for Android named AnubisSpy.
The Trend Micro team evaluated seven apps on Google Play and third‑party stores discovering AnubisSpy. These apps were written in Arabic so they are related to Egypt, even mentioned in Egypt’s daily news and Egyptian TV shows. The apps had fake Google certificates and were installed mainly by users in Eastern countries.
AnubisSpy can steal SMS messages, contacts, photos, videos, email accounts, browser histories, screen screenshots, and files from Twitter, Facebook, Skype and WhatsApp. The most interesting thing, however, is that it has a self‑destruct option to hide its traces and delete data on infected devices. The file structure, the decryption method (.JSON), and the C&C servers it uses to manage its entire strategy resemble the operation of Sphinx Malware, which uses the watering‑hole technique to infect users. In the image below you can see its structure.
Regarding the date the malicious applications appeared, the researchers stated that they date back to April 2015 and the most recent variant was released in October 2017. Trend Micro contacted Google and asked it to upgrade Google Play Protect in order to prevent the installation of applications that contain AnubisSpy.


