logo

Malicious Document Reader App in Google Play With 50K Downloads Installs Anatsa Malware

ID: 03b25e0f-f852-5f9d-9526-e81128322986

STIX ID: report--03b25e0f-f852-5f9d-9526-e81128322986

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-12-08

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Zscaler ThreatLabz identified a deceptive Google Play app (“Document Reader – File Manager”) that downloads the Anatsa/TeaBot banking trojan after install; the report describes the trojan’s credential theft, keylogging and overlay phishing capabilities, advanced evasion (runtime string decryption, emulator checks, malformed ZIPs), permissions abuse (accessibility, SYSTEM_ALERT_WINDOW, READ_SMS), and provides specific IOCs (package name, installer/payload MD5s, download URL, and C2 server IPs) to support detection and forensics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.