216.73.217.22

Android Document Readers and Deception: Tracking the Latest Updates to Anatsa

· Published 22/08/2025 23:28 · Modified 25/08/2025 11:03

Export JSON

Essential information

Published
22/08/2025 23:28
Modified
25/08/2025 11:03
Tags
2025-08-22 anatsa android banking trojan coper credential-theft cryptocurrency evasion techniques facestealer financial institutions google play store harly joker teabot
Related entities
1 intrusion sets (apt), 6 malware, 2 others

Description

, an banking malware first discovered in 2020, has evolved with new capabilities and targets. The latest variant now affects over 831 worldwide, including new countries and platforms. has streamlined its payload delivery, implemented DES runtime decryption, and added device-specific restrictions. The malware uses decoy applications in the , some exceeding 50,000 downloads. Alongside , 77 other malicious apps from various families were identified, totaling over 19 million installs. 's include emulation checks, device model verification, and the use of malformed archives to hide malicious code. The malware primarily steals credentials through fake banking login pages tailored to detected financial apps on the user's device.

External references