Malicious Document Reader App in Google Play With 50K Downloads Installs Anatsa Malware
An Android application, masquerading as a document reader and file manager, has been identified on the Google Play Store as delivering the Anatsa banking trojan. The app, named "Document Reader – File Manager," developed by ISTOQMAH, has exceeded 50,000…
An Android application, masquerading as a document reader and file manager, has been identified on the Google Play Store as delivering the Anatsa banking trojan. The app, named "Document Reader – File Manager," developed by ISTOQMAH, has exceeded 50,000 downloads, deceiving users into granting permissions that facilitate financial data theft.
Originally detected by cybersecurity firm Zscaler ThreatLabz, this malware campaign underscores ongoing challenges in securing official app stores against sophisticated threats.
First identified in 2020, Anatsa, also known as TeaBot, is an Android banking malware designed for credential theft, keylogging, and executing fraudulent transactions targeting financial applications. Recent updates have expanded its reach to over 831 institutions globally, including regions such as Germany and South Korea, and cryptocurrency platforms.
The Trojan incorporates advanced evasion techniques, including runtime DES decryption, device model checks to avoid emulators, and malformed ZIP archives for concealing DEX payloads, which evade static analysis tools.
The dropper app presents itself as a legitimate tool for opening PDFs, scanning documents, and managing files, featuring an intuitive interface. Once installed, it discreetly downloads the Anatsa payload from a command-and-control server, bypassing Play Store protections. If the payload checks fail, the app displays a fake file manager interface to maintain its disguise.
Upon activation, Anatsa seeks accessibility permissions to auto-grant dangerous privileges, such as SYSTEM_ALERT_WINDOW, READ_SMS, and full-screen intents, enabling it to overlay phishing pages tailored to detected banking apps.
Zscaler ThreatLabz has provided specific indicators of compromise (IOCs) for this wave of Anatsa, assisting in its detection. The app's promotional claims of being an "all-in-one solution" for documents conceal its malicious activities.
Recent updates have expanded its reach to over 831 institutions globally, including regions such as Germany and South Korea, and cryptocurrency platforms.
This application joins numerous similar decoys, with ThreatLabz reporting 77 malicious apps with a total of 19 million installs recently removed from Google Play. Anatsa campaigns frequently utilize productivity apps, such as document viewers, exploiting user trust in utility tools.
Users are at risk of stolen banking credentials through fake logins or automated fraud, particularly in North America, where previous strains ranked high in "Free Tools" sections. Despite enhancements to Google Play Protect, timely reports from researchers remain vital.
Android users are advised to scrutinize app permissions, avoid unsolicited updates, and employ antivirus scanners. Security teams can utilize these IOCs for network monitoring and device forensics.
Indicator Value
Package Name com.quantumrealm.nexdev.quarkfilerealm_filedoctool G7qS0W6bMAEE2v4.jpg
Installer MD5 98af36a2ef0b8f87076d1ff2f7dc9585
Payload MD5 da5e24b1a97faeacf7fb97dbb3a585af
Download URL https://quantumfilebreak[.]com/txt.txt
C2 Servers http://185.215.113[.]108:85/api/
For further updates, follow us on Google News , LinkedIn , and X . For story submissions, contact us .
Based on reporting by Cyber Security News.
