{"id":2397,"date":"2025-03-06T10:09:58","date_gmt":"2025-03-06T10:09:58","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/03\/06\/android-app-with-220000-downloads-from-google-play-installs-banking-trojan\/"},"modified":"2025-03-06T10:09:58","modified_gmt":"2025-03-06T10:09:58","slug":"android-app-with-220000-downloads-from-google-play-installs-banking-trojan","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/03\/06\/android-app-with-220000-downloads-from-google-play-installs-banking-trojan\/","title":{"rendered":"Android App With 220,000+ Downloads From Google Play Installs Banking Trojan"},"content":{"rendered":"<p>    Android App With 220,000+ Downloads From Google Play Installs Banking Trojan<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated Android banking trojan campaign leveraging a malicious file manager application accumulated over 220,000 downloads on the Google Play Store before its removal.\u00a0<\/p>\n<p>Dubbed Anatsa (also known as TeaBot), the malware targets global financial institutions through a multi-stage infection process. It deploys fake login overlays and abuses accessibility services to steal credentials and execute unauthorized transactions.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Anatsa\u2019s Attack Chain<\/strong><\/h2>\n<p>According to the Zscaler ThreatLabz post shared on X, the malicious app, disguised as a \u201cFile Manager and Document Reader,\u201d functioned as a dropper, a seemingly benign application that retrieves and installs additional payloads from remote servers.\u00a0<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXePGBEvs0V_1zB9-LtGUiHluxQB_Aifk_M2xSMEnht1KB9XwcaZWTJg2KggulYUY2GQAayT1re4E801AlVHKVBrJs-MWmLceROcILHk1YrftZiihbtyypGMKrwNbFwlkRAo_Zyx?key=cAE0r6MhFBwGe-yFEv1Hplrg\" alt=\"\"><figcaption class=\"wp-element-caption\">App disguised as a file manager and document reader<\/figcaption><\/figure>\n<p>The app prompted users to download a fraudulent \u201cupdate\u201d masquerading as a necessary add-on upon installation. This update, hosted on GitHub repositories, contained the Anatsa banking trojan.<\/p>\n<p>Anatsa employs reflection-based code execution to dynamically load malicious Dalvik Executable (DEX) files, which evade static analysis tools by decrypting payloads only at runtime.\u00a0<\/p>\n<p>The malware performs anti-emulation checks to detect sandboxed environments, delaying malicious activity until it confirms a genuine device. Once active, it requests critical permissions, including:<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Accessibility Services:<\/strong> To log <a href=\"https:\/\/cybersecuritynews.com\/snake-keylogger-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\">keystrokes<\/a>, intercept SMS messages, and manipulate screen content.<\/li>\n<li>\n<strong>SMS Access:<\/strong> To bypass two-factor authentication (2FA) mechanisms<\/li>\n<\/ul>\n<p>The trojan then establishes communication with <a href=\"https:\/\/cybersecuritynews.com\/command-and-controlc2-server\/\" target=\"_blank\" rel=\"noreferrer noopener\">command-and-control (C2) servers<\/a>, transmitting device metadata and receiving targeted banking app profiles.\u00a0<\/p>\n<p>For each detected financial app (e.g., PayPal, HSBC, Santander), Anatsa injects a counterfeit login overlay, capturing credentials directly from unsuspecting users.<\/p>\n<p>Anatsa\u2019s latest campaign has primarily targeted users in Europe, including Slovakia, Slovenia, and Czechia, though its infrastructure supports expansion into the U.S., South Korea, and Singapore.\u00a0<\/p>\n<p>The malware\u2019s target list encompasses over 600 banking and cryptocurrency apps, enabling threat actors to conduct on-device fraud (ODF) by initiating unauthorized transfers via automated transaction systems (ATS).<\/p>\n<h2 class=\"wp-block-heading\">\n<strong>Mitigations<\/strong>\u00a0<\/h2>\n<p>To mitigate risks, users should:<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Avoid sideloading:<\/strong> Disable \u201cInstall from unknown sources\u201d in device settings.<\/li>\n<li>\n<strong>Audit app permissions:<\/strong> Revoke accessibility and SMS access for non-essential apps.<\/li>\n<li>\n<strong>Monitor for updates:<\/strong> Legitimate apps update via official stores, not third-party links.<\/li>\n<\/ul>\n<p>The Anatsa campaign underscores persistent gaps in app store security, particularly regarding delayed payload attacks.\u00a0<\/p>\n<p>While Google has removed the identified dropper, similar threats remain prevalent, often exploiting file managers and utility apps to evade suspicion.\u00a0<\/p>\n<p>For end-users, vigilance and adherence to basic security hygiene remain critical defenses against evolving <a href=\"https:\/\/cybersecuritynews.com\/top-5-mobile-security-threats\/\" target=\"_blank\" rel=\"noreferrer noopener\">mobile threats<\/a>.<\/p>\n<p><strong>Indicators of Compromise (IoCs):<\/strong><\/p>\n<p><strong>Network:<\/strong><\/p>\n<pre class=\"wp-block-preformatted\">hxxps:\/\/docsresearchgroup[.]com<br>http:\/\/37.235.54[.]59\/<br>http:\/\/91.215.85[.]55:85<\/pre>\n<p><strong>Sample MD5s:<\/strong><\/p>\n<pre class=\"wp-block-preformatted\">a4973b21e77726a88aca1b57af70cc0a<br>ed8ea4dc43da437f81bef8d5dc688bdb<\/pre>\n<p class=\"has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong><strong><code>Collect Threat Intelligence on the Latest Malware and Phishing Attacks with ANY.RUN TI Lookup -&gt;\u00a0<a href=\"https:\/\/intelligence.any.run\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=new-stegocampaign-attack&amp;utm_content=intelligence.any.run&amp;utm_term=040325\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try for free<\/a><\/code><\/strong><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/android-app-with-220000-downloads\/\">Android App With 220,000+ Downloads From Google Play Installs Banking Trojan<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/android-app-with-220000-downloads\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Android App With 220,000+ Downloads From Google Play Installs Banking Trojan A sophisticated Android banking trojan campaign leveraging a malicious file manager application accumulated over 220,000 downloads on the Google Play Store before its removal.\u00a0 Dubbed Anatsa (also known as TeaBot), the malware targets global financial institutions through a multi-stage infection process. It deploys fake [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,258,873],"tags":[130],"class_list":["post-2397","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-malware","category-today-cyber-attack-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2397"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=2397"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2397\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=2397"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=2397"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=2397"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}