logo

Anatsa Android malware downloaded 150,000 times via Google Play

ID: 788adf9f-0d12-5b5e-b142-457ed65d4db8

STIX ID: report--788adf9f-0d12-5b5e-b142-457ed65d4db8

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2024-02-19

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

The report details a Google Play–hosted campaign distributing the Anatsa banking trojan to users across several European countries via fake PDF viewers and cleaner apps; operators used a multi-stage downloader and abused Android's AccessibilityService to install the infostealer, with an estimated 150k–200k downloads. Google removed most apps and users are advised to scrutinize permissions and publishers to reduce risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.