New Wave of 'Anatsa' Banking Trojans Targets Android Users in Europe
ID: c9a6106b-93e6-58ca-b749-f62793f59abd
STIX ID: report--c9a6106b-93e6-58ca-b749-f62793f59abd
Feed Name: Dark Reading
Threat Score
ThreatFabric observed a multi-wave campaign (since Nov 2023) delivering the Anatsa banking trojan through Play Store droppers disguised as cleaners and PDF apps; droppers dynamically fetch DEX payloads from a C2 and abuse Android AccessibilityService to install the infostealer, resulting in over 100,000 installs across several European countries and enabling credential theft and bank account takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
