Evolution of Zanubis, a banking Trojan for Android

May 28, 2025, 8:34 p.m.

Description

Zanubis is an evolving Android banking Trojan that emerged in 2022, targeting financial institutions in Peru before expanding to virtual cards and crypto wallets. It impersonates legitimate apps to trick users into granting accessibility permissions, enabling extensive data theft and device control. The malware has undergone significant development, incorporating features like SMS hijacking, screen recording, and device credential stealing. Recent versions show improved obfuscation, encryption, and silent installation techniques. The threat actors, likely based in Peru, continue to refine the malware's capabilities and targeting strategy, focusing on high-value financial targets in the region.

Date

  • Created: May 28, 2025, 5:57 p.m.
  • Published: May 28, 2025, 5:57 p.m.
  • Modified: May 28, 2025, 8:34 p.m.

Indicators

  • c9c454913ce6062a4387a92283b80e62391751b31a9b22ac9aa27dcc3edd3b4f
  • a9916294cdc4de511fa09f441093456bb488928519a79ac950ad116adef981ee
  • a1af1cc7d4e90083f7d90bc6eaa884146bcd21b2c76641e03c326f0cc1dc1e68
  • 8e83e6544c5b8d92360e6f8f8777be655d4ecf16e38b58c8d5bf2e76b224f6fb
  • 7b9f3d2d8a39d3cdc268c8fa5a5a51986a183266e5194ffcb53257d4219d287b
  • 712b2d385b578fe9fa2bc404ef27b9204a0c67e4ded6129975e6f0464983ff10
  • 52537ae43cc20c6c408dffddb83cc785cd942f43282047c4e48448f6576a75bd
  • 4d2ef8f7dcc4b39436062e5666cbf5e3d41f990a272b16660418ee60bde6cdd1

Attack Patterns

  • Zanubis
  • Zanubis

Additional Informations

  • Finance
  • Peru