logo

Fake Document Reader On Google Play With 10K Downloads Installing Anatsa Malware

ID: 1d2f1252-05e7-5b78-b4ee-991322d23554

STIX ID: report--1d2f1252-05e7-5b78-b4ee-991322d23554

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Tushar Subhra Dutta

...
...

A malicious Android app masquerading as a file/document reader on Google Play distributed the Anatsa banking trojan, achieving over 10,000 installs before removal; the report details the two-stage dropper delivery, accessibility- and SMS-based credential theft, obfuscation/evasion techniques (runtime DEX, corrupted ZIP, emulation checks), targeted banking and crypto platforms, C2 infrastructure and IOCs, and recommends uninstalling the app, reviewing permissions, and scanning affected devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.