#Anatsa
Anatsa: PDF-Viewer leert Bankkonten / Android-Usern

Der Banking-Trojaner Anatsa landet aktuell über die Installation von Apps wie PDF Viewer oder PDF Reader von Google Play Store beim User.
https://tarnkappe.info/artikel/it-sicherheit/anatsa-pdf-viewer-leert-bankkonten-von-android-usern-288880.html
Anatsa: PDF-Viewer leert Bankkonten von Android-Usern
Der Banking-Trojaner Anatsa landet aktuell über die Installation von Apps wie PDF Viewer oder PDF Reader von Google Play Store beim User.
tarnkappe.info
February 3, 2024 at 8:10 PM
ThreatFabric says the Anatsa Android banking trojan is now being used to target American and Canadian banks.

The kicker—infected apps are available via the official Play Store

www.threatfabric.com/blogs/anatsa...
Anatsa Targets North America; Uses Proven Mobile Campaign Process
Anatsa targets North America again: ThreatFabric uncovers a new Android banking Trojan campaign using Google Play to compromise mobile banking apps.
www.threatfabric.com
July 8, 2025 at 12:56 PM
Malicious apps with +19M installs removed from Google Play because spreading Anatsa banking trojan and other malware

Experts found 77 malicious Android apps with 19M+ installs on Google Play, spreading malware, including the Anatsa (TeaBot) banking trojan. While investigating An…

#hackernews #news
Malicious apps with +19M installs removed from Google Play because spreading Anatsa banking trojan and other malware
Experts found 77 malicious Android apps with 19M+ installs on Google Play, spreading malware, including the Anatsa (TeaBot) banking trojan. While investigating Anatsa (Tea Bot) banking trojan infections, Zscaler’s ThreatLabs discovered seventy-seven malicious Android apps with more than 19 million installs. Several Anatsa decoy apps have each been downloaded more than 50,000 times. The malicious apps […]
securityaffairs.com
August 26, 2025 at 3:54 PM
⚠️ Google eradicates TeaBot Threat

#Google has purged 77 malicious apps from #PlayStore (combined downloads exceeding 19M) that embedded the Anatsa/TeaBot #malware, targeting over 831 global financial institutions.

Play Protect had already been blocking these threats.

#ransomNews #TeaBot
August 25, 2025 at 8:37 AM
IT-Forscher haben eine starke Verbreitung der Anatsa-Malware entdeckt. Sie steckt in mehr als 90 Apps auf Google Play mit 5,5 Millionen Downloads. #Security
Google Play Store: Malware in 90 Apps mit 5,5 Millionen Installationen
IT-Forscher haben eine starke Verbreitung der Anatsa-Malware entdeckt. Sie steckt in mehr als 90 Apps auf Google Play mit 5,5 Millionen Downloads.
www.heise.de
May 30, 2024 at 12:53 PM
Researchers: the Anatsa banking trojan snuck into Google Play once again via an app disguised as a PDF viewer, which had 50K+ downloads before Google removed it (Bill Toulas/BleepingComputer)

Main Link | Techmeme Permalink
July 9, 2025 at 8:40 AM
Anatsa malware continues to evolve, targeting over 831 financial institutions worldwide. Stay vigilant and protect your Android device. #CyberSecurity #Anatsa #AndroidMalware #BankingTrojan Link: thedailytechfeed.com/anatsa-malwa...
August 22, 2025 at 3:55 PM
[BleepingComputer]Anatsa Android trojan now steals banking info from users in US, UK - BleepingComputer A new mobile malware campaign since March 2023 pushes the Android banking trojan 'Anatsa' to online banking customers in the U.S., the U.K., Germany, Austria, and Switzerland.
June 28, 2023 at 8:45 PM
Anatsa Malware Attacking Android Devices to Steal Login Credentials and Monitor Keystrokes
Anatsa Malware Attacking Android Devices to Steal Login Credentials and Monitor Keystrokes
cybersecuritynews.com
August 22, 2025 at 8:37 AM
Anatsa Android Banking Malware from Google Play Targeting Users in the U.S. and Canada
Anatsa Android Banking Malware from Google Play Targeting Users in the U.S. and Canada
cybersecuritynews.com
July 8, 2025 at 4:51 PM
Fake Document Reader On Google Play With 10K Downloads Installing Anatsa Malware
Fake Document Reader On Google Play With 10K Downloads Installing Anatsa Malware
A new fake document reader app found on the Google Play Store has been silently installing Anatsa, a powerful Android banking trojan, on thousands of user devices. The malicious application surpassed 10,000 downloads before Google removed it, putting a significant number of Android users at direct risk of financial fraud and credential theft. Anatsa is not a new name in mobile security. The malware first surfaced in 2020 as an Android banking trojan built to steal credentials, record keystrokes, and perform fraudulent transactions on infected devices without user knowledge. Over the years, it has grown into one of the most persistent mobile banking threats, with its latest variant now targeting more than 831 financial institutions globally, including newly added banks and cryptocurrency platforms in countries like Germany and South Korea. Researchers at Zscaler ThreatLabz identified the malicious application on the Google Play Store and published their findings on April 27, 2026. The app was disguised as a file reader under the package name  com.groundstation.informationcontrol.filestation_browsefiles_readdocs  and had surpassed 10,000 downloads before Google removed it from the platform. This incident is yet another chapter in Anatsa’s ongoing campaign, which has repeatedly used benign-looking utility apps to bypass app store defenses and reach real users at scale. ThreatLabz discovered another fake document reader in the Google Play Store with more than 10K downloads, which delivered the Anatsa Android trojan. Anatsa installer SHA256 hash: 5c9b09819b196970a867b1d459f9053da38a6a2721f21264324e0a8ffef01e20 Payload URL:… pic.twitter.com/CBAgWfaa4n — Zscaler ThreatLabz (@Threatlabz) April 27, 2026 The app used a dropper technique to stay undetected during the store’s review process. Once installed, it appeared to work normally as a document reader, showing no signs of malicious activity . In the background, it connected to a remote server and pulled down the Anatsa payload from  http://23.251.108[.]10:8080/privacy.txt , silently installing the trojan without any user-visible alerts. This two-stage delivery is designed to beat app store reviews that only assess apps at the point of submission. This method of staying clean at first and then downloading malware later has been a signature of Anatsa’s campaigns for years. Since Google Play’s security scans focus on the initial version of an app, the trojan can enter the platform undetected and wait until it has enough installations before activating. By that point, the malware is already running on thousands of real devices. Infection Mechanism and Detection Evasion Once Anatsa’s payload is running on a device, it requests accessibility permissions from the user. If granted, the malware automatically activates a broader set of privileges, including overlaying content on top of other apps, intercepting SMS messages, and displaying full-screen alerts. These capabilities are used to capture user activity, steal banking credentials, and interfere with legitimate app interactions without raising obvious alarms. To stay hidden from security tools, Anatsa hides its DEX file inside a corrupted ZIP archive with invalid compression flags. The file only executes at runtime and is deleted immediately after loading, making it very difficult for static tools to catch. The payload is further embedded inside a JSON file that is dropped and erased during execution, leaving minimal evidence of the infection on the device. Anatsa encrypts all traffic to its command-and-control servers using a single-byte XOR key. In this campaign, the C2 servers were hosted at  http://172.86.91[.]94/api/ ,  http://193.24.123[.]18:85/api/ , and  http://162.252.173[.]37:85/api/ . These servers deliver fake banking login overlays that appear directly over legitimate banking apps, tricking users into entering their credentials on fraudulent pages that look completely real. The malware also performs emulation checks and verifies the device model before deploying the payload. If it detects a sandboxed or testing environment, it simply displays a clean file manager interface instead of launching the trojan. This built-in self-defense mechanism helps Anatsa remain undetected during automated analysis, giving it more time to operate freely on real user devices without being flagged. Android users should review the permissions any new app requests before approving them. Document readers and file managers have no legitimate reason to request accessibility permissions or SMS access. Keeping Google Play Protect turned on, avoiding apps from unfamiliar developers, and questioning any app that asks for unusual permissions are all practical steps worth taking. Anyone who installed the affected application should uninstall it immediately and scan their device with a trusted mobile security tool . Indicators of Compromise (IOCs):- Indicator Type Detail 5c9b09819b196970a867b1d459f9053da38a6a2721f21264324e0a8ffef01e20 Installer SHA256 Anatsa dropper hash 88fd72ac0cdab37c74ce14901c5daf214bd54f64e0e68093526a0076df4e042f Payload SHA256 Anatsa core payload hash http://23.251.108[.]10:8080/privacy.txt Payload URL Remote payload delivery server http://172.86.91[.]94/api/ C2 Server Anatsa command-and-control http://193.24.123[.]18:85/api/ C2 Server Anatsa command-and-control http://162.252.173[.]37:85/api/ C2 Server Anatsa command-and-control com.groundstation.informationcontrol.filestation_browsefiles_readdocs Package Name Malicious dropper app (removed) Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google . The post Fake Document Reader On Google Play With 10K Downloads Installing Anatsa Malware appeared first on Cyber Security News .
cybersecuritynews.com
April 28, 2026 at 6:13 AM
⚠️❗️⚠️❗️⚠️❗️⚠️❗️⚠️

Scheinbar harmloser PDF-Viewer leert Bankkonten ahnungsloser Android-Nutzer:innen
👀👀👀👀👀👀👀👀

www.watchlist-internet.at/news/scheinb...
Scheinbar harmloser PDF-Viewer leert Bankkonten ahnungsloser Android-Nutzer:innen - Watchlist Intern...
Derzeit ist eine neue Welle von Schadsoftware im Umlauf, die bereits in der Vergangenheit zahlreiche Bankkonten leergeräumt hat. Es handelt sich dabei um den Banking-Trojaner Anatsa, der über die In...
www.watchlist-internet.at
February 4, 2024 at 4:01 PM
Android users warned of 'malicious' virus stealing bank details - fake app to delete
Android users warned of 'malicious' virus stealing bank details - fake app to delete
Android users are being warned about a fake app that downloads a Trojan virus called Anatsa to devices and then steals bank details.
dlvr.it
July 5, 2026 at 10:15 PM
Android malware Anatsa infiltrates Google Play to target US banks 🕵️‍♂️🔥

The Anatsa banking trojan has sneaked into #Google Play once more via an app posing as a #PDF viewer that counted more than 50,000 downloads! 📲🤳 📄

#CyberSec #TechNews #news #cybercrime

www.bleepingcomputer.com/news/securit...
Android malware Anatsa infiltrates Google Play to target US banks
The Anatsa banking trojan has sneaked into Google Play once more via an app posing as a PDF viewer that counted more than 50,000 downloads.
www.bleepingcomputer.com
July 9, 2025 at 8:01 AM

🚨 Alert: Anatsa dropper apps bypass #Google Play protections and #Android 13 restrictions, now targeting users in Slovakia, Slovenia, and Czechia to steal banking information.
thehackernews.com/2024/02/anat...
#cybersecurity #hacking
Anatsa Android Trojan Bypasses Google Play Security, Expands Reach to New Countries
Anatsa Android banking trojan expands to Slovakia, Slovenia, Czechia.
thehackernews.com
February 19, 2024 at 9:18 PM
90+ Malicious Apps Totaling 5.5M Downloads Lurk on Google Play
90+ Malicious Apps Totaling 5.5M Downloads Lurk on Google Play
The dangerous Anatsa banking Trojan is among the malware being spread to Android users via decoy mobile apps in recent months.
www.darkreading.com
May 28, 2024 at 3:07 PM
Im Google Play Store tauchen Varianten des Anatsa-Banking-Trojaners auf. Sie kommen auf über 100.000 Installationen.
Google Play Store: Banking-Trojaner nimmt europäische Nutzer ins Visier
Im Google Play Store tauchen Varianten des Anatsa-Banking-Trojaners auf. Sie kommen auf über 100.000 Installationen.
www.heise.de
February 22, 2024 at 9:50 AM
Over 90 malicious Android apps with 5.5M installs found on Google Play
Over 90 malicious Android apps with 5.5M installs found on Google Play
Over 90 malicious Android apps were found installed over 5.5 million times through Google Play to deliver malware and adware, with the Anatsa banking trojan seeing a recent surge in activity.
www.bleepingcomputer.com
May 28, 2024 at 9:52 PM
We need to have a word about installing extra apps on your phone. Many of these that are free apps to install, which seem to be giving you some benefit, ARE still costing you something. Typically that's your data. Think about it, all it takes is ONE update to an app to turn it into malware. Cont'd 👇
January 24, 2026 at 6:15 PM
This is so ridiculous that this type of malware is still possible in the Play Store. Also worth noting that this could not happen on iPhone because apps are sandboxed and require explicit permissions, unlike Android. #cybersecurity www.bleepingcomputer.com/news/securit...
Android malware Anatsa infiltrates Google Play to target US banks
The Anatsa banking trojan has sneaked into Google Play once more via an app posing as a PDF viewer that counted more than 50,000 downloads.
www.bleepingcomputer.com
July 9, 2025 at 1:28 AM
--Anatsa banking trojan has sneaked into Google Play as a PDF viewer,
--Novel tapjacking technique can bypass Android permissions,
--IBM's new datacenter chips offer improved security,
--Data stolen for Gloucester Co. employees, 4/5
July 9, 2025 at 1:21 PM
Die IT-Sicherheitsexperten der ZScaler ThreatLabz haben in den vergangenen Monaten mehr als 90 bösartige Apps im Google Play Store entdeckt und analysiert. Insgesamt kamen die Malware-infizierten Apps auf mehr als 5,5 Millionen Installationen.
Android-Malware: 90 Apps mit 5,5 Millionen Installationen entdeckt
IT-Forscher haben eine starke Verbreitung der Anatsa-Malware entdeckt. Sie steckt in mehr als 90 Apps auf Google Play mit 5,5 Millionen Downloads.
www.heise.de
May 30, 2024 at 2:20 PM