VYPR
breachPublished Oct 9, 2026· 1 source

Malicious PDF Reader on Google Play Delivers Anatsa Banking Trojan

A malicious Android PDF reader app, installed over 10,000 times on Google Play, has been identified as a dropper for the Anatsa banking trojan, targeting user financial credentials.

A malicious Android PDF reader app, downloaded by over 10,000 users from the Google Play Store, has been identified as a sophisticated delivery mechanism for the Anatsa banking trojan. This discovery highlights how seemingly innocuous utility applications can be weaponized to compromise users' financial information.

The app, disguised as a legitimate PDF reader, functions as a dropper. Upon installation, it serves as a conduit to download and install the actual Anatsa banking malware. Once active, the trojan attempts to steal sensitive banking credentials by presenting users with fake login pages that mimic legitimate financial applications.

Researchers from Zscaler ThreatLabz uncovered this campaign, detailing the malicious components and their command-and-control (C2) infrastructure. They provided file hashes for both the installer app and the Anatsa payload, along with the URLs used by the malware to communicate with its operators. The scale of installs, exceeding 10,000, indicates a significant potential reach for this threat.

This is not the first time Anatsa has been distributed through deceptive apps. In April, a similar campaign involving a fake document reader was identified and subsequently removed by Google. However, the current campaign utilizes a different package and installer, underscoring the persistent efforts of threat actors to evade detection.

Anatsa, also known by the alias TeaBot, employs a modular approach. The initial dropper app is distinct from the final banking trojan payload, a tactic that can help evade initial security scans. ThreatLabz's analysis of previous Anatsa variants revealed techniques such as checking the device environment to avoid sandboxes and using obfuscated or encrypted code to hinder analysis.

While the exact number of successful infections, compromised accounts, or affected financial institutions remains unconfirmed for this specific campaign, the known capabilities of Anatsa pose a substantial risk. Previous versions have been documented to request intrusive permissions like SMS and accessibility access, which are then used to intercept sensitive data and present fake login screens.

Users who may have installed the identified PDF reader app are strongly advised to remove it immediately. They should also review the permissions granted to all applications and run a security scan on their devices. Enabling Google Play Protect and exercising caution with requests for elevated permissions are crucial preventative measures.

For security professionals, the provided indicators of compromise, including package names, file hashes, and C2 addresses, are vital for detecting and mitigating this threat within their networks. Network traffic analysis can help identify devices that have communicated with the malicious infrastructure.

Synthesized by Vypr AI