Malware

Anatsa Android trojan now steals banking information

0

A new mobile malware campaign pushes the Android banking trojan ‘Anatsa’ to online banking customers in the U.S., the U.K., Germany, Austria, and Switzerland since March 2023.

The security researchers at ThreatFabric have been tracking this malicious activity and according to them the attackers are distributing their malware via the Play Store, Android’s official app store. There have already been over 30,000 installations through this method alone.

ThreatFabric discovered a previous Anatsa campaign on Google Play in November 2021, when the trojan was installed over 300,000 times by impersonating PDF scanners, QR code scanners, Adobe Illustrator apps, and fitness tracker apps.

In March 2023, the threat actors launched a new malvertizing campaign that leads the victims to download Anatsa dropper apps from Google Play.

The malicious apps are of the office/productivity category, posing as PDF viewer and editor apps and office suites.

Whenever ThreatFabric reported the malicious app to Google, it was removed from the store, but the attackers returned quickly by uploading a new dropper under a new guise.

The apps were submitted onto Google Play in clean form and were later updated with malicious code, in order to evade Google’s stringent code review process on the first submission.

Once installed on the victim’s device, the dropper apps request an external resource hosted on GitHub, from where they download the Anatsa payloads disguised as text recognizer add-ons for Adobe Illustrator.

Anatsa collects financial information such as bank account credentials, credit card details, payment information, etc., by overlaying phishing pages on the foreground when the user attempts to launch their legitimate bank app and also via keylogging.

In the latest version, the Anatsa trojan supports targeting nearly 600 financial apps of banking institutions from around the world.

The stolen information is used to perform on-device fraud by launching the banking app and performing transactions on the victim’s behalf, automating the money-stealing process for its operators.

The stolen amounts are converted to cryptocurrency and passed through an extensive network of money mules in the targeted countries, who will keep a portion of the stolen funds as a revenue share and send the rest to the attackers.

All of these identified malicious apps have been removed from Google Play and the developers have been banned.

Image Credits : Cyclonis

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Man charged for running ‘Monopoly’ darknet drug market

Previous article

How burglars use Social Media and its effects

Next article

You may also like

More in Malware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *