• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
anatsa android banking trojan hits 90,000 users with fake pdf

Anatsa Android Banking Trojan Hits 90,000 Users with Fake PDF App on Google Play

You are here: Home / General Cyber Security News / Anatsa Android Banking Trojan Hits 90,000 Users with Fake PDF App on Google Play
July 8, 2025

Cybersecurity researchers have discovered an Android banking malware campaign that has leveraged a trojan named Anatsa to target users in North America using malicious apps published on Google’s official app marketplace.

The malware, disguised as a “PDF Update” to a document viewer app, has been caught serving a deceptive overlay when users attempt to access their banking application, claiming the service has been temporarily suspended as part of scheduled maintenance.

“This marks at least the third instance of Anatsa focusing its operations on mobile banking customers in the United States and Canada,” Dutch mobile security company ThreatFabric said in a report shared with The Hacker News. “As with previous campaigns, Anatsa is being distributed via the official Google Play Store.”

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Anatsa, also referred to as TeaBot and Toddler, has been known to be active since at least 2020, typically delivered to victims via dropper apps.

Cybersecurity

Early last year, Anatsa was found to have targeted Android device users in Slovakia, Slovenia, and Czechia by first uploading benign apps masquerading as PDF readers and phone cleaners to the Play Store and then introducing malicious code a week after release.

Like other Android banking trojans, Anatsa is capable of providing its operators with features designed to steal credentials through overlay and keylogging attacks, and conduct Device-Takeover Fraud (DTO) to initiate fraudulent transactions from victim’s devices.

ThreatFabric said Anatsa campaigns follow a predictable, but well-oiled, process that involves establishing a developer profile on the app store and then publishing a legitimate app that works as advertised.

“Once the application gains a substantial user base – often in the thousands or tens of thousands of downloads – an update is deployed, embedding malicious code into the app,” the company said. “This embedded code downloads and installs Anatsa on the device as a separate application.”

The malware then receives a dynamic list of targeted financial and banking institutions from an external server, enabling the attackers to perform credential theft for account takeover, keylogging, or fully automated transactions using DTO.

A crucial factor that allows Anatsa to evade detection as well as maintain a high success rate is its cyclical nature where the attacks are interspersed by periods of no activity.

The newly discovered app targeting North American audiences masquerades as a Document Viewer (APK package name: “com.stellarastra.maintainer.astracontrol_managerreadercleaner”) and is published by a developer named “Hybrid Cars Simulator, Drift & Racing.” Both the app and the associated developer account are no longer accessible on the Play Store.

Statistics from Sensor Tower show that the app was first published on May 7, 2025, reaching the fourth spot in the “Top Free – Tools” category on June 29, 2025. It’s estimated to have been downloaded around 90,000 times.

“This dropper followed Anatsa’s established modus operandi: initially launched as a legitimate app, it was transformed into a malicious one approximately six weeks after release,” ThreatFabric said. “The distribution window for this campaign was short yet impactful, running from 24 to 30 June.”

Cybersecurity

The Anatsa variant, per the company, is also configured to target a broader set of banking apps in the United States, reflective of the malware’s increasing focus on exploiting financial entities in the region.

Another clever feature incorporated into the malware is its ability to display a fake maintenance notice when trying to access the target banking application. This tactic not only conceals the malicious activity occurring within the app, but also prevents customers from contacting the bank’s support team, thereby delaying detection of financial fraud.

“The latest operation not only broadened its reach but also relied on well-established tactics aimed at financial institutions in the region,” ThreatFabric said. “Organizations in the financial sector are encouraged to review the provided intelligence and assess any potential risks or impacts on their customers and systems.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «malicious pull request infects 6,000+ developers via vulnerable ethcode vs Malicious Pull Request Infects 6,000+ Developers via Vulnerable Ethcode VS Code Extension
Next Post: Hackers Use Leaked Shellter Tool License to Spread Lumma Stealer and SectopRAT Malware hackers use leaked shellter tool license to spread lumma stealer»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.