Digital image showing Google Play icon, trojan malware code, and a bank to highlight Android banking trojan risks

Anatsa Trojan Hidden in Popular Play Store Document App

Category: Cybersecurity

A fake document reader on Google Play has infected thousands of Android devices with the Anatsa banking trojan. Security researchers at Zscaler ThreatLabz discovered the malicious app disguised as a file manager tool with more than 50,000 installs. The app tricks users into granting permissions that expose financial accounts to credential theft and automated fraud. The campaign shows how well executed decoy apps still slip through marketplace controls despite stronger screening.

Relevant Source (Zscaler ThreatLabz): Technical Analysis of Anatsa Campaigns: An Android Banking Malware Active in the Google Play Store
This Zscaler analysis shows how fake PDF and document-style apps on Google Play act as droppers for the Anatsa banking trojan, matching the malicious document reader scenario in this section.

Quick Facts

  • Malicious app posed as “Document Reader – File Manager”
  • More than 50,000 downloads on Google Play
  • Delivered the Anatsa (TeaBot) banking trojan
  • Stole banking credentials using overlays and keylogging
  • Used evasion tactics like DES runtime decryption and anti-emulation checks
  • Pulled payloads from remote C2 servers after installation

Evolving Anatsa Banking Threat

Anatsa banking malware continues to evolve with new delivery techniques. The trojan specializes in credential theft and automated financial transactions that mimic user behavior during fraud attempts. Researchers have tracked its expansion across more than 831 financial institutions worldwide including banks, credit unions and crypto platforms. Attackers hide payloads inside malformed ZIP files that bypass static scanning which makes detection harder for app store security systems.

  • Anatsa now targets Germany, South Korea and cryptocurrency services
  • The dropper app was developed by “ISTOQMAH”
  • Payload downloads were disguised as routine updates

The scale of distribution proves how dangerous common-looking utility apps can become when users trust store listings without reviewing permissions or developer identity.

Relevant Source (Zscaler ThreatLabz): Anatsa’s Latest Updates
This report shows that Anatsa now targets over 831 financial and cryptocurrency institutions worldwide, confirming its expanded reach and the use of decoy document apps on Google Play.

Why Anatsa Threatens Users

A malicious document app may sound like a niche concern, yet the impact reaches anyone who relies on mobile banking. Anatsa abuses Android accessibility permissions to overlay fake login screens on top of legitimate banking apps. These overlays collect usernames, passwords and session data with precision that defeats basic fraud checks. Zscaler noted that similar campaigns were found across 77 apps with more than 19 million combined installs.

  • Overlay attacks steal credentials in real time
  • SMS access helps intercept one-time passcodes
  • SYSTEM_ALERT_WINDOW permissions enable forced popups
  • Emulation checks bypass analyst sandboxes
  • Payloads activate only when conditions are safe for attackers

Strong marketplace defenses help, but malicious apps still reach users when decoys blend into popular tool categories like file managers, document viewers or PDF scanners.

Relevant Source (Verimatrix): Decoding a Mobile Banking App Overlay Attack
This article explains how Android banking trojans abuse accessibility services and overlay fake login screens to steal banking credentials, matching the risks described in this section.

Immediate Android Safety Steps

Android owners can reduce exposure by reviewing app permissions and uninstalling anything that requests access unrelated to its primary purpose. A basic document reader does not need SMS access or full accessibility control. Trusted antivirus scanners can flag dangerous behaviors before malware activates. Security teams should load the published indicators of compromise into monitoring tools.

Steps for users:

  1. Check for suspicious apps under Settings → Apps
  2. Revoke unnecessary accessibility permissions
  3. Run a mobile antivirus scan
  4. Remove the app if package name matches listed indicators
  5. Reset banking credentials on all affected accounts

Users who uninstall the app should still change passwords because Anatsa may harvest credentials before removal.

Relevant Source (CISA): Privacy and Mobile Device Apps
This CISA guidance urges users to review app permissions and remove apps with excessive access, directly supporting the need to uninstall suspicious Android apps and limit risky permissions.

Android Malware And Permissions

Anatsa’s success highlights long-standing problems with Android’s permission model. Utility apps often request broad access to files, notifications and accessibility services which creates ideal cover for malware droppers. Attackers lean on this trust because users rarely question why a simple document reader needs deep system privileges. The resulting attacks hit banking customers who assume Play Store vetting is enough to guarantee safety.

The industry faces a persistent battle as threat actors adapt faster than automated review systems. Malformed ZIP files, encrypted strings and selective activation make malicious behavior invisible during testing. Researchers continue to report new variants that slip into productivity categories where users seldom expect risk. Better user awareness and stricter permission policies reduce exposure but cannot remove the threat entirely.

Relevant Source (Tom’s Guide): Over 200 malicious apps were downloaded more than 40 million times from the Google Play Store this year
This report covers Zscaler’s findings that hundreds of malicious apps with millions of installs slipped through Google Play reviews, highlighting systemic risks in Android’s app and permission model.

Android Security Hygiene Tips

Staying safe on Android requires a habit of checking what an app wants access to before tapping Install. A normal file manager should never ask for SMS access or full accessibility control. Users who remove suspicious apps and reset credentials can limit the damage. Security researchers will continue uncovering these threats, but individual device hygiene still matters.

Relevant Source (McAfee): How to Stay Safe While Using Third-Party Apps
This guide stresses reviewing app permissions, deleting risky apps and using mobile security software, which aligns directly with the practical cleanup and protection steps in this section.

Common Questions

How did the fake app bypass Google’s protections?
The malware used encrypted strings, malformed ZIP payloads and behavior that activated only after installation which reduced detection during automated scans.

What data can Anatsa steal?
It can capture login credentials, intercept SMS codes, log keystrokes and execute fraudulent transactions through accessibility automation.

How many devices were affected?
The dropper app had more than 50,000 installs, though the full infection count depends on how many users granted permissions.

Can Play Protect stop this malware?
Play Protect blocks many threats but cannot stop every new variant. User reviews, permission checks and antivirus tools add extra protection.

What should I do if I installed the app?
Uninstall it immediately, run a mobile antivirus scan and change your banking passwords. Contact your bank if you notice any suspicious activity.

Trojan Malware: Risks, How It Works, Prevention

JENI Systems And Device Safety

Android threats like Anatsa show how fast malicious apps evolve and how easily they slip into trusted platforms. Devices stay safer when maintenance, cleanup and repair work happen consistently without relying on cloud tools or risky third-party processes. JENI helps keep systems stable which reduces the impact of malware, corrupted files and performance problems that often hide early warning signs.

How JENI Strengthens System Reliability

  • Cleans deep system caches that can hide corrupted data
  • Repairs stability issues that slow device performance
  • Restores predictable operation that supports safer daily use

JENI gives users a simple way to maintain a clean and stable device environment which lowers the risk of overlooked system problems. Smooth performance makes suspicious activity easier to spot early. Local processing avoids exposure to external servers which strengthens privacy. Strong system hygiene will not stop malware on its own yet it reduces the conditions that allow threats to linger unnoticed.

Published on December 8, 2025 at 12:04 PM by:

Geoffrey has decades of hands-on experience in IT, software development, and cybersecurity, bringing expert technical insight to every article. He holds two IT bachelor’s degrees, a business degree, and a master’s degree in Cybersecurity and Information Assurance.