The infamous banking trojan Anatsa has reappeared on Google Play, this time disguised as a viewer app PDF called Document Viewer – File Reader. The app had garnered more than 50,000 downloads before it was detected and removed by Google.

According to Threat Fabric , which detected the malicious activity and promptly notified Google, the trojan is activated immediately after the application is installed. Its goal is to spy on users' banking transactions in North American banking applications , displaying an overlay that aims to steal credentials, record keystrokes , or even automate transaction execution .
See also: SpyNote: Targets users through fake Google Play pages
How the scam works
When a user opens a targeted banking application, the Anatsa banking trojan displays a fake scheduled maintenance message, completely covering the graphical interface of the authentic application. This tactic hides the trojan and prevents users from detecting unauthorized actions or contacting their bank directly.
The app uploaded to the Play Store by the publisher “Hybrid Cars Simulator, Drift & Racing” initially appeared legitimate. The perpetrators, as they have done in previous campaigns, avoided introducing the malicious code in the first place, first allowing the app to gain credibility and recognition through positive reviews and a large number of installs.
See also: Google Play: Over 300 malicious apps found with 60 million downloads
Once the app became popular, a malicious payload via an update retrieved from a remote server and installed as a second application, without the user being notified. The Anatsa banking trojan then connected to a command–and–control (C2) infrastructure, receiving a list of specific apps to monitor.
History of Invasions – Anatsa Persists
Anatsa has appeared on Google Play several times before. Since 2021, multiple infection campaigns fake app:
- November 2021 – 300,000 downloads
- June 2023 – 30,000 downloads
- February 2024 – 150,000 downloads
- May 2024 – 70,000 downloads via two applications (PDF reader & QR scanner)

The latest malicious Document Viewer – File Reader was introduced between June 24 and 30, 2025, approximately six weeks after the original legitimate app. The app has now been removed by Google.
How to protect yourself – What to do if you have it installed
Google recommends that users:
- Uninstall the application
- Run a full scan with Google Play Protect
- Change banking credentials
Additionally, it urges users to be especially wary of apps that request excessive permissions or appear to be from unknown publishers. Reviews, screenshots, and an app's release date can be useful signs to identify suspicious cases.
See also: North Korean hackers “uploaded” spyware to Google Play
The use of reliable security software and regular updates of the operating system and applications are also essential .
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
