Malicious Google Play App With 50K+ Downloads Spreads Anatsa Banking Trojan
A malicious application on the Google Play Store has been identified as a document reader but functions as a dropper for the Anatsa banking trojan. This malware has been downloaded over 50,000 times and is designed to target financial institutions and…
A malicious application on the Google Play Store has been identified as a document reader but functions as a dropper for the Anatsa banking trojan. This malware has been downloaded over 50,000 times and is designed to target financial institutions and compromise user banking credentials.
The app employs social engineering tactics by disguising itself as a legitimate document reader, thereby posing a significant risk to Android users. It mimics the functionality of genuine document management tools while covertly deploying the Anatsa banking malware. This approach allows threat actors to evade Google Play Store's security mechanisms and reach a wide user base before the malicious activity is detected.
ThreatLabz researchers identified that the application uses sophisticated obfuscation techniques to hide its malicious payload from security scanners and manual analysis.
Anatsa Trojan Targets Banking Credentials
The dropper mechanism is engineered to retrieve additional malware components after the initial installation. This design allows threat actors to maintain flexibility and adapt their tactics to bypass new security measures.
Anatsa is a well-known banking trojan active since 2019, targeting financial institutions in Europe, the Middle East, and parts of Asia. It has advanced capabilities, including overlay attacks, automatic transaction authentication compromise, and credential harvesting. The trojan can intercept SMS messages, monitor user activities, and execute unauthorized transactions on compromised devices.
The discovery of this malicious app represents a significant security risk for Android users , as it bypassed Google's security review process and was downloaded 50,000 times. Users who installed the app are advised to uninstall it immediately.
Device owners should conduct a security scan with reputable mobile security solutions to identify and remove any potential malware. Monitoring banking accounts for unauthorized transactions and contacting financial institutions if suspicious activity is detected is also recommended.
A malicious application on the Google Play Store has been identified as a document reader but functions as a dropper for the Anatsa banking trojan.
Google's security team has removed the malicious application from the Play Store and revoked the associated developer account credentials. This incident highlights the need for enhanced security review processes and machine learning-based detection systems to identify sophisticated malware during app submissions.
Security experts advise Android users to adopt a multi-layered security approach, including updating operating systems with the latest security patches, installing apps from official channels, using reputable mobile security software, and regularly monitoring account activity. Caution should be exercised when granting app permissions, and regular reviews of these permissions are recommended.
The discovery of the Anatsa dropper on Google Play Store underscores the persistent threats faced by official app stores from sophisticated actors. Organizations and users must remain vigilant and maintain a robust security posture to protect against evolving banking malware threats.
Type Description Value
Installer MD5 Anatsa malware installer hash 1991f5d0c88d8c7c68f6a6d27efa60d6
Download URL Source link for the installer https://stellargridinv[.]com/
Payload MD5 Anatsa main payload hash 7f131404a331ae10fdc76bfe5908575d
C2 Server 1 Command and Control endpoint http://193.24.123[.]18:85/api/
C2 Server 2 Command and Control endpoint http://162.252.173[.]37:85/api/
Based on reporting by GBHackers.
