logo

10,000 Users Exposed As Fake Document Reader App Delivers Anatsa Banking Trojan

ID: 1857b1fb-9fca-5f1c-846d-444d68104d4d

STIX ID: report--1857b1fb-9fca-5f1c-846d-444d68104d4d

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Varshini

...
...

Security researchers uncovered a fake document reader app on Google Play (com.groundstation.informationcontrol.filestation_browsefiles_readdocs) that installed the Anatsa Android banking trojan via a second-stage payload download; the trojan abuses Accessibility Services and overlay attacks to steal banking credentials and perform unauthorized transfers, and the report provides installer/payload SHA256 hashes, payload and C2 URLs, and recommends removal and account monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.