Anatsa’s Latest Updates
ID: 9b4da0db-dc84-5ac4-b954-9479646954e5
STIX ID: report--9b4da0db-dc84-5ac4-b954-9479646954e5
Feed Name: Zscaler Security Research Blog
Technical analysis of the Anatsa Android banking trojan: the report describes an installer that performs emulation and device-model checks, decrypts strings at runtime with a generated DES key, and downloads a DEX payload hidden in JSON and a malformed APK/ZIP to evade static and dynamic analysis. Once installed it requests accessibility and SMS permissions, enables manifest permissions, deploys a keylogger and banking-page injection framework tailored to detected financial apps, and communicates with C2 servers using a single-byte XOR (sample C2 IPs/domains are provided).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
