Blog
BankBot Anubis Switches to Chinese and Adds Telegram for C2
Tue, 01/29/2019
We've recently noticed two significant changes in C2 tactics used by the threat actors behind BankBot Anubis, a mobile banking trojan. First is the use of Chinese characters to encode the C2 strings (in addition to base64 encoding). The second is the use of Telegram Messenger in addition to Twitter for communicating C2 URLs.
Previously reported by PhishLabs, the criminals behind BankBot...