Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Malicious Document Reader App in Google Play With 50K Downloads Installs Anatsa Malware

An Android application, masquerading as a document reader and file manager, has been identified on the Google Play Store as delivering the Anatsa banking trojan. The app, named "Document Reader – File Manager," developed by ISTOQMAH, has exceeded 50,000…

An Android application, masquerading as a document reader and file manager, has been identified on the Google Play Store as delivering the Anatsa banking trojan. The app, named "Document Reader – File Manager," developed by ISTOQMAH, has exceeded 50,000 downloads, deceiving users into granting permissions that facilitate financial data theft.

Originally detected by cybersecurity firm Zscaler ThreatLabz, this malware campaign underscores ongoing challenges in securing official app stores against sophisticated threats.

First identified in 2020, Anatsa, also known as TeaBot, is an Android banking malware designed for credential theft, keylogging, and executing fraudulent transactions targeting financial applications. Recent updates have expanded its reach to over 831 institutions globally, including regions such as Germany and South Korea, and cryptocurrency platforms.

The Trojan incorporates advanced evasion techniques, including runtime DES decryption, device model checks to avoid emulators, and malformed ZIP archives for concealing DEX payloads, which evade static analysis tools.

The dropper app presents itself as a legitimate tool for opening PDFs, scanning documents, and managing files, featuring an intuitive interface. Once installed, it discreetly downloads the Anatsa payload from a command-and-control server, bypassing Play Store protections. If the payload checks fail, the app displays a fake file manager interface to maintain its disguise.

Upon activation, Anatsa seeks accessibility permissions to auto-grant dangerous privileges, such as SYSTEM_ALERT_WINDOW, READ_SMS, and full-screen intents, enabling it to overlay phishing pages tailored to detected banking apps.

Zscaler ThreatLabz has provided specific indicators of compromise (IOCs) for this wave of Anatsa, assisting in its detection. The app's promotional claims of being an "all-in-one solution" for documents conceal its malicious activities.

Recent updates have expanded its reach to over 831 institutions globally, including regions such as Germany and South Korea, and cryptocurrency platforms.
Joseph Cain · Thehackingpost

This application joins numerous similar decoys, with ThreatLabz reporting 77 malicious apps with a total of 19 million installs recently removed from Google Play. Anatsa campaigns frequently utilize productivity apps, such as document viewers, exploiting user trust in utility tools.

Users are at risk of stolen banking credentials through fake logins or automated fraud, particularly in North America, where previous strains ranked high in "Free Tools" sections. Despite enhancements to Google Play Protect, timely reports from researchers remain vital.

Android users are advised to scrutinize app permissions, avoid unsolicited updates, and employ antivirus scanners. Security teams can utilize these IOCs for network monitoring and device forensics.

Indicator Value

Package Name com.quantumrealm.nexdev.quarkfilerealm_filedoctool G7qS0W6bMAEE2v4.jpg

Advertisement

Installer MD5 98af36a2ef0b8f87076d1ff2f7dc9585

Payload MD5 da5e24b1a97faeacf7fb97dbb3a585af

Download URL https://quantumfilebreak[.]com/txt.txt

C2 Servers http://185.215.113[.]108:85/api/

For further updates, follow us on Google News , LinkedIn , and X . For story submissions, contact us .

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories