The TeaBot banking trojan has been spotted again on the Google Play Store disguised as a QR code app. It is said to have spread to more than 10,000 devices.
It's a trick its distributors had used earlier, in January, and although Google removed those listings, the malware still managed to make its way into the Play Store.
See also: Nvidia confirms data breach after cyberattack

According to a report by Cleafy, an online fraud management and prevention company, these types of apps operate as droppers. They are submitted without malicious code and request minimal permissions. For this reason, Google’s checks have a hard time detecting anything suspicious. Furthermore, trojanized apps deliver the functionality they promise, so users don’t notice anything and their reviews on the Play Store are positive.
Play Store app distributes TeaBot trojan
In February, researchers found that TeaBot was appearing as an app called “QR Code & Barcode – Scanner,” which appears to be a legitimate QR code scanning program.
During installation, the application requests an update through a message it displays, but contrary to the standard procedure imposed by Play Store guidelines, the update is obtained from an external source.
Cleafy traced the download source to two GitHub repositories owned by the same user (feleanicusor) and containing multiple TeaBot samples (uploaded on February 17, 2022).
Once the victim accepts the update from the external, untrusted source, TeaBot is loaded onto their device as a new application named “QR Code Scanner: Add-On.”
The new application opens automatically and asks the user to grant permission to use Accessibility Services. This allows the TeaBot trojan to do the following:
- Monitoring the device screen and taking screenshots that expose login credentials, 2FA codes, SMS content, etc.
- Performing actions, such as automatically granting additional permissions, in the background without requiring user interaction.
See also: Chinese cyberspies target governments with 'most advanced' backdoor
In Android 12, Google has introduced some changes to the Accessibility Service API (for security purposes). However, most Android phones are still running Android 11 or earlier.

TeaBοt banking trojan: Targets
In versions released on the Play Store in January 2021 (analyzed by Bitdefender), TeaBot avoided targeting victims in the United States.
Now, however, it appears that TeaBot is actively targeting users in the US and has also added Russian, Slovak, and Chinese, indicating that the malware is targeting users around the world.
See also: Banking malware: The most dangerous trojans that have ever existed!
Perhaps TeaBot operators now feel they have created a more powerful malware. Compared to early 2021 samples, the malware now features stronger string obfuscation and targets 500% more (from 60 to 400) banking, insurance, crypto wallet, and crypto exchange applications.
To minimize the chances of infection by banking trojans like TeaBot, don't download too many apps to your device (even from the Play Store). Also, whenever you install a new app, monitor battery consumption and network traffic volume for the first two days to detect any suspicious patterns.
Source: Bleeping Computer
