logo

Over 90 malicious Android apps with 5.5M installs found on Google Play

ID: dc461abe-3718-5630-9b93-f67b84bc0fcf

STIX ID: report--dc461abe-3718-5630-9b93-f67b84bc0fcf

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-05-28

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Over 90 malicious Android apps — including recent Google Play dropper apps for the Anatsa (Teabot) banking trojan — were discovered, collectively installed some 5.5 million times; Anatsa uses a four-stage DEX-based loader with anti-analysis checks to fetch and install the banking payload, exfiltrate app and device data to C2, and download region-appropriate injection modules to steal credentials and conduct fraud. The two identified Anatsa dropper apps had about 70,000 installs before removal, highlighting active distribution via official app stores and significant risk to users' financial accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.