logo

Anatsa’s Latest Updates

ID: 9b4da0db-dc84-5ac4-b954-9479646954e5

STIX ID: report--9b4da0db-dc84-5ac4-b954-9479646954e5

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-08-21

Date Updated: 2026-05-01

...
...

Technical analysis of the Anatsa Android banking trojan: the report describes an installer that performs emulation and device-model checks, decrypts strings at runtime with a generated DES key, and downloads a DEX payload hidden in JSON and a malformed APK/ZIP to evade static and dynamic analysis. Once installed it requests accessibility and SMS permissions, enables manifest permissions, deploys a keylogger and banking-page injection framework tailored to detected financial apps, and communicates with C2 servers using a single-byte XOR (sample C2 IPs/domains are provided).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.