Anatsa Campaign Technical Analysis
ID: 6486ad90-4a39-54e4-8f61-174053e08dca
STIX ID: report--6486ad90-4a39-54e4-8f61-174053e08dca
Feed Name: Zscaler Security Research Blog
Threat Score
This report provides a technical analysis of the Anatsa mobile banking trojan campaign, describing a multi-stage Android dropper that downloads and loads encrypted DEX payloads from C2 servers, uses anti-analysis and corrupted APK/ZIP headers to hinder inspection, requests SMS and accessibility permissions, enumerates installed financial apps, and serves fraudulent login pages via webviews to harvest banking credentials which are sent to the C2.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
