HomeSecurityAnatsa banking trojan: Targets users in the US and Europe

Anatsa banking trojan: Targets users in the US and Europe

A new malware distribution campaign that has been underway since March 2023 is distributing the Android banking Trojan “Anatsa” to customers using online banking in the US, UK , Germany, Austria, and Switzerland.

Anatsa banking trojan

According to security researchers at ThreatFabric, the attackers are distributing the malware via the Play Store. The trojan has had at least 30,000 installations via malicious apps that have infiltrated the app store.

ThreatFabric also discovered a previous Anatsa distribution campaign on Google Play in November 2021. At least 300,000 Android devices. The malicious apps impersonated PDF scanners, QR code scanners, Adobe Illustrator apps, and fitness tracking apps.

See also: Super Mario 3: Mario Forever – Malicious version infects Windows devices

Android banking Trojan “Anatsa”: New campaign

In March 2023, threat actors launched a new Anatsa distribution campaign, leading potential victims to download Anatsa dropper apps from Google Play.

And in this new campaign, malicious applications appear as legitimate PDF viewing and editing applications and office suites

In fact, the attackers are particularly persistent. Every time ThreatFabric researchers found a malicious app and reported it to Google (which took care of removing it from Google Play), the attackers quickly returned with a new dropper.

At least five malware droppers have been identified . The malicious apps were submitted to Google Play in their pure form and later acquired the malicious code through updates . Apparently, the apps were “pure” upon initial submission, to avoid Google’s rigorous code review process at this early stage.

Once installed on the victim's device, the dropper applications request an external resource hosted on GitHub, where they download Anatsa payloads disguised as text recognizer add-ons for Adobe Illustrator.

Anatsa banking trojan collects financial information such as banking credentials , credit card details, payment details, etc. by displaying pages phishing when the user attempts to open a legitimate banking application. It also uses keylogging techniques .

See also: NSA: To kill BlackLotus malware, patch is a good start

In its current version, the Anatsa trojan can target at least 600 banking institution applications from around the world.

The Anatsa banking trojan uses the stolen financial information to commit fraud on the device, opening the banking application used by the victim and making transactions on behalf .

Android adware

Since the transactions are initiated from the same device that targeted bank customers regularly use, it is very difficult for banking systems to detect the fraud,” ThreatFabric explains.

The stolen funds are converted into crypto and passed through an extensive network of money mules in the targeted countries. These networks keep a portion of the stolen funds and send the rest to the attackers.

How to protect yourself?

The Anatsa Android banking trojan reminds us once again that we need to be extra careful with the applications we download to Android devices

Choose to download apps only from trusted sources, but avoid installing apps from questionable publishers, even if they are in official app stores like Google Play. reviews user and check for reports of strange or malicious behavior.

See also: Powerful JavaScript Dropper PindOS Distributes Bumblebee and IcedID Malware

Additionally, avoid apps with few installs and reviews and choose more well-known apps.

As many apps on Google Play have the same name as malicious apps, check the ThreatFabric report to find the list of package names and signatures that distribute Anatsa.

If you have a malicious app on your Android device, remove it immediately.

It is a good idea to also have an antivirus application on your mobile device to increase security levels .

Android banking trojans are one of the most significant threats in recent times, due to their ability to steal sensitive information from users' mobile devices. With millions of people using mobile banking apps, it is important to remain vigilant and know how to protect ourselves from such attacks.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS