Anatsa Android Trojan Bypasses Google Play Security, Expands Reach to New Countries
ID: 4a82f94d-59c2-569b-aa1d-5de7d4d04da6
STIX ID: report--4a82f94d-59c2-569b-aa1d-5de7d4d04da6
Feed Name: The Hacker News
The report describes a November 2023 campaign distributing the Anatsa (TeaBot/Toddler) Android banking trojan via Google Play dropper apps that abused the accessibility API and versioning to dynamically fetch payloads and bypass Android 13 restrictions; the campaign targeted several European countries (Slovakia, Slovenia, Czechia) and involved multiple droppers with over 100,000 installs across them, stole credentials and enabled fraudulent transactions, and included identified package names that were removed from Google Play.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
