HomeSecurityGoogle Play: Malicious app with 50,000 downloads distributed by Anatsa malware

Google Play: Malicious app with 50,000 downloads distributed by Anatsa malware

The highly dangerous banking malware Anatsa was recently detected on the Google Play Store, causing great concern in the cybersecurity community. Before it was removed, the malicious app had already exceeded 50,000 downloads, proving once again that even the most “trusted” platforms are not invulnerable.

Anatsa banking malware looked like an innocent application

The application appeared as a simple document reader, targeting users looking for everyday productivity tools. The choice of this type of application was not accidental, as PDF readers and file editors are considered low-risk and rarely raise suspicion.

This strategy allowed cybercriminals to bypass users' suspicions by exploiting the trust that comes with applications available through Google Play.

See also: deVixor: New Android banking malware

Official app stores as a vehicle for attacks

The incident highlights a worrying pattern: attackers are increasingly turning to official app stores as a primary distribution channel. Despite automated and manual security filters, malicious developers continue to find ways to hide the true purpose of their software.

Google Play Removes malware

This specific case raises serious questions about the adequacy of control mechanisms and the need for more aggressive behavioral detection methods.

What is the Anatsa banking trojan?

Anatsa belongs to the banking trojan category and is designed with one clear goal: stealing banking credentials and financial data. Unlike simpler threats, it initially operates as a dropper, i.e. an installer that downloads the full malicious payload after successful installation.

Once it obtains the necessary permissions, Anatsa activates advanced monitoring functions, without the user being aware of its activity.

How users unintentionally grant access

Users who installed the fake app granted elevated access permissions. These permissions paved the way for financial fraud, data mining, and possible full bank account.

See also: FvncBot: New Android banking malware steals data

The presence of the app on Google Play reinforced the sense of security, making the attack extremely effective on a massive scale.

Zscaler ThreatLabz research

Zscaler ThreatLabz analysts were the ones who identified the threat and immediately began monitoring the distribution infrastructure and command and control (C2) servers. The investigation revealed a direct connection of Anatsa to organized bank fraud operations.

At the same time, technical indicators of compromise (IOCs) were published, enabling other security teams to identify infected devices and limit the damage.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

How does the infection mechanism work?

Once installed, Anatsa embeds itself deeply into the Android operating system and continuously monitors user activity . It places particular emphasis on banking applications , enabling overlay attacks and data logging techniques.

When the user enters passwords, card numbers, or login details, the malware collects them in real time and sends them to external servers controlled by the attackers.

Google Play: Malicious app with 50,000 downloads distributed by Anatsa malware

Continuous control from threatening factors

Communicating with specific IP addresses allows attackers to maintain constant control over infected devices. This means that attacks are not instantaneous, but evolve dynamically, with a continuous flow of data and session tokens to criminal networks.

See also: New improved version of TgToxic banking malware

What users should do

Experts recommend immediately uninstalling suspicious apps, especially document readers of unknown origin. Additionally, it is critical to verify apps through official sources and enable multi-factor authentication (MFA) on all bank accounts.

The Anatsa incident is yet another reminder that digital security is not a given – not even within the most well-known app stores.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS