Anatsa Banking Malware: Google Play Apps Exposed
ID: 835a48a2-dffe-58b7-925a-867811c9d64f
STIX ID: report--835a48a2-dffe-58b7-925a-867811c9d64f
Feed Name: CyberNexora News
Anatsa (TeaBot) is an Android banking Trojan distributed via apparently legitimate Google Play applications (e.g., PDF/document readers) that act as loaders and use staged delivery and deceptive update prompts to install the malicious payload. The malware employs overlay attacks to capture login credentials and targets financial applications, creating risks of unauthorized account access, fraud, and business/reputational impact; the report outlines the infection chain, mitigation advice, and notes no specific technical IoCs were included.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
