Malicious Google Play App With 50K+ Downloads Spreads Anatsa Banking Trojan
ID: 2e322480-006f-5f63-bf15-6054376baea9
STIX ID: report--2e322480-006f-5f63-bf15-6054376baea9
Feed Name: GBHackers
Threat Score
A malicious document-reader app on the Google Play Store functioned as a dropper for the Anatsa banking trojan, collecting over 50,000 downloads before removal; the report details the dropper’s obfuscation, multi-stage payload retrieval, Anatsa’s banking-focused capabilities (overlay attacks, SMS interception, credential theft), and supplies IOCs (installer and payload MD5s, download URL, and two C2 endpoints).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
