logo

Anatsa Campaign Technical Analysis

ID: 6486ad90-4a39-54e4-8f61-174053e08dca

STIX ID: report--6486ad90-4a39-54e4-8f61-174053e08dca

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report provides a technical analysis of the Anatsa mobile banking trojan campaign, describing a multi-stage Android dropper that downloads and loads encrypted DEX payloads from C2 servers, uses anti-analysis and corrupted APK/ZIP headers to hinder inspection, requests SMS and accessibility permissions, enumerates installed financial apps, and serves fraudulent login pages via webviews to harvest banking credentials which are sent to the C2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.