Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Cheers co-creator and Friends director James Burrows dies at 85

Rich bassist Sixpence None dies at age 50

Dawn the Duck joins Scotland’s tartan army as unofficial mascot

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » FIN7 deploys Anubis Backdoor to hijack Windows systems through compromised SharePoint sites
Celebrities

FIN7 deploys Anubis Backdoor to hijack Windows systems through compromised SharePoint sites

By April 2, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

April 2, 2025Ravi LakshmananRansomware/Email Security

Hijack your Windows system

A financially motivated threat actor known as FIN7 is linked to a Python-based backdoor called Anubis (not to be confused with Android Banking Trojan of the same name) that allows remote access to compromised Windows systems.

“The malware allows an attacker to perform remote shell commands and other system operations to give him complete control over the infected machine,” Swiss Cybersecurity Company Prodaft said in a technical report for the malware.

Cybersecurity

FIN7 is also known as Carbon Spider, Elbras, Gold Niagara, Sangria Tempest, and Savage Ten Bug, a Russian cybercrime group known for its evolving and expanding set of malware families to obtain early access and data exfoliation. In recent years, it is said that threat actors have moved to ransomware affiliate marketing.

In July 2024, the group was observed to promote a tool called Aukill (aka Avneutralizer), which can use a variety of online aliases to terminate security tools in attempts that could diversify their monetization strategies.

Anubis is usually thought to be propagated through the Malspam campaign, which entices victims to run payloads hosted on the compromised SharePoint site.

The entry point for infections delivered in the form of zip archives is a Python script designed to directly decrypt and execute the major obfuscated payloads in memory. Upon booting, the backdoor establishes communication with the remote server via a TCP socket in Base64 encoded format.

Also, responses from the base 64 encoded server collect the host’s IP address, upload/download the file, change the current working directory, change the grab environment variables, change the Windows registry, load the DLL file into memory using PythonMemoryModule and exit.

Cybersecurity

In an independent analysis of Anubis, German security company GDATA said that the backdoor also supports the ability to perform responses provided by operators as shell commands for the victim system.

“This allows attackers to take actions such as keylogging, taking screenshots, and stealing passwords without storing these features directly on the infected system,” Prodaft said. “By keeping the backdoor as light as possible, we reduce the risk of detection while still maintaining the flexibility to carry out even malicious activities.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleStephen Curry’s 52 points: Warriors win against the Grizzlies | Basketball News
Next Article The EU proposes flexibility in vehicle CO2 emission targets

Related Posts

Adria Arjona’s red Roberto Cavalli dress at the ‘Supergirl’ fan event

June 19, 2026

Jason Momoa’s daughter wears wired headphones as an accessory

June 19, 2026

Rama Dowaj Styles Upcycled Knicks Shirt by Claire Sullivan

June 18, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Cheers co-creator and Friends director James Burrows dies at 85

Rich bassist Sixpence None dies at age 50

Dawn the Duck joins Scotland’s tartan army as unofficial mascot

Prime Day Early Adult Toy Sale: Shop LELO, Womanizer and more

Trending Posts

Rich bassist Sixpence None dies at age 50

June 19, 2026

Adria Arjona’s red Roberto Cavalli dress at the ‘Supergirl’ fan event

June 19, 2026

Jason Momoa’s daughter wears wired headphones as an accessory

June 19, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.