s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.zanubis

📛 Threat Title

Malware family: Zanubis

Category: Zanubis First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.zanubis`. Printable name: Zanubis.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.zanubis VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.zanubis

IOC database

Type
domain
Value
apk.zanubis
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.zanubis

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.zanubis

References (1)

Remediations (10)

  • web:cyberpress.org

    A new ransomware collective dubbed Anubis has rapidly emerged as a sophisticated threat actor, combining ransomware-as-a-service (RaaS) operations with data extortion and access monetization strategies. Active since at least November 2024, the group targets critical sectors like healthcare and construction while employing Russian-language communications across dark web forums. Security ...

  • web:cybershafarat.com

    Zanubis's obfuscation routines, algorithmic upgrades, and behavioral engineering are not the outcome of cybercriminal tinkering. They reflect continuous versioning by a technically mature organization managing full lifecycle malware operations. Kaspersky's public framing of Zanubis as an evolving third-party threat masks its direct role in coding, testing, and deploying the Trojan across ...

  • web:github.com

    Android - Remote Access Trojan List. Contribute to wishihab/Android-RATList development by creating an account on GitHub.

  • web:imtr.net

    # Tool/Technique: Zanubis (Banking Trojan) ## Overview The subject of the analysis is ** Zanubis **, identified as an evolution of a banking Trojan specifically targeting the **Android** platform. The purpose of this malware is likely financial fraud through compromising banking applications on infected devices.

  • web:securelist.com

    In this report, we share our latest crimeware findings: the ASMCrypt cryptor/loader related to DoubleFinger, a new Lumma stealer and a new version of Zanubis Android banking trojan.

  • web:www.cybersecurity-review.com

    Zanubis is a banking Trojan for Android that emerged in mid-2022. Since its inception, it has targeted banks and financial entities in Peru, before expanding its objectives to virtual cards and crypto wallets. The main infection vector of Zanubis is impersonating legitimate Peruvian Android applications and then misleading the user into enabling the accessibility permissions. Once these ...

  • web:www.kaspersky.co.uk

    The ever-evolving landscape of malware , exemplified by the multifaceted Lumma stealer and the ambitions of Zanubis as a full-fledged banking Trojan, underscores the dynamic nature of these threats. Adapting to this constant transformation in malicious code and cybercriminal tactics poses an ongoing challenge for defense teams.

  • web:www.kaspersky.com

    Kaspersky Global Research and Analysis Team (GReAT) discovered a new version of the Zanubis mobile banking trojan targeting users in Peru. When Zanubis originally emerged in 2022, it mimicked PDF readers or Peru government organizations' apps, and now in 2025 it disguises itself as two new apps - one of a local company in the energy sector and the other - of a local bank. With advanced ...

  • web:www.pcrisk.com

    What is Zanubis ? Zanubis is a piece of malicious software classified as a banking trojan. This malware targets Android Operating Systems (OSes). The primary function of this program is to stealthily obtain online banking account credentials and gain access to the funds stored therein. Zanubis targets Latin American banks, particularly those based in Peru. Zanubis malware overview As is common ...

  • web:zimperium.com

    Kaspersky recently published an in-depth analysis of Zanubis , an evolving Android banking trojan primarily targeting users in Latin America. Initially masquerading as legitimate Peruvian government apps, Zanubis has continued to evolve its tactics and infrastructure, now distributing malware through deceptive websites and exploiting ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.