logo

Malicious Google Play App With 50K+ Downloads Spreads Anatsa Banking Trojan

ID: 2e322480-006f-5f63-bf15-6054376baea9

STIX ID: report--2e322480-006f-5f63-bf15-6054376baea9

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-02-03

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A malicious document-reader app on the Google Play Store functioned as a dropper for the Anatsa banking trojan, collecting over 50,000 downloads before removal; the report details the dropper’s obfuscation, multi-stage payload retrieval, Anatsa’s banking-focused capabilities (overlay attacks, SMS interception, credential theft), and supplies IOCs (installer and payload MD5s, download URL, and two C2 endpoints).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.