HomeSecurityAnatsa: Banking trojan reappears on Google Play

Anatsa: Banking trojan reappears on Google Play

The infamous banking trojan Anatsa has reappeared on Google Play, this time disguised as a viewer app PDF called Document Viewer – File Reader. The app had garnered more than 50,000 downloads before it was detected and removed by Google.

Anatsa banking trojan Google Play

According to Threat Fabric , which detected the malicious activity and promptly notified Google, the trojan is activated immediately after the application is installed. Its goal is to spy on users' banking transactions in North American banking applications , displaying an overlay that aims to steal credentials, record keystrokes , or even automate transaction execution .

See also: SpyNote: Targets users through fake Google Play pages

How the scam works

When a user opens a targeted banking application, the Anatsa banking trojan displays a fake scheduled maintenance message, completely covering the graphical interface of the authentic application. This tactic hides the trojan and prevents users from detecting unauthorized actions or contacting their bank directly.

The app uploaded to the Play Store by the publisher “Hybrid Cars Simulator, Drift & Racing” initially appeared legitimate. The perpetrators, as they have done in previous campaigns, avoided introducing the malicious code in the first place, first allowing the app to gain credibility and recognition through positive reviews and a large number of installs.

See also: Google Play: Over 300 malicious apps found with 60 million downloads

Once the app became popular, a malicious payload via an update retrieved from a remote server and installed as a second application, without the user being notified. The Anatsa banking trojan then connected to a command–and–control (C2) infrastructure, receiving a list of specific apps to monitor.

History of Invasions – Anatsa Persists

Anatsa has appeared on Google Play several times before. Since 2021, multiple infection campaigns fake app:

  • November 2021 – 300,000 downloads
  • June 2023 – 30,000 downloads
  • February 2024 – 150,000 downloads
  • May 2024 – 70,000 downloads via two applications (PDF reader & QR scanner)
Anatsa: Banking trojan reappears on Google Play

The latest malicious Document Viewer – File Reader was introduced between June 24 and 30, 2025, approximately six weeks after the original legitimate app. The app has now been removed by Google.

How to protect yourself – What to do if you have it installed

Google recommends that users:

Additionally, it urges users to be especially wary of apps that request excessive permissions or appear to be from unknown publishers. Reviews, screenshots, and an app's release date can be useful signs to identify suspicious cases.

See also: North Korean hackers “uploaded” spyware to Google Play

The use of reliable security software and regular updates of the operating system and applications are also essential .

Source: www.bleepingcomputer.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS