Fake Document Reader in The Google Play Store with 100K Downloads Deliver Android Malware
ID: b0904849-0333-5c5a-bd86-a77a78a0583d
STIX ID: report--b0904849-0333-5c5a-bd86-a77a78a0583d
Feed Name: cybersecurityNews.com
A malicious dropper app masquerading as a document reader on the Google Play Store is distributing the Anatsa/TeaBot banking trojan, which has been downloaded over 100,000 times and targets more than 831 financial services; the malware fetches its payload from remote servers, evades analysis (runtime string decryption, corrupted ZIP payloads, package/hash rotation), requests accessibility and SMS permissions to enable overlays and keylogging for credential theft and fraudulent transactions, and the report includes multiple IoCs (MD5 hashes, C2 URLs, and the malicious package name) and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
