Dangerous Android malware targets US banking apps – 50,000 people already affected, make sure you’re not next


- Security researchers found a PDF app for Android sporting a banking trojan
- The trojan was introduced with a patch, six weeks after release
- It had more than 50,000 downloads, so users should beware
A dangerous Android banking trojan has found a way to the Google Play Store once again, potentially affecting tens of thousands of North American users, experts have warned.
Security researchers from Threat Fabric found an app on the Play Store, called ‘Document Viewer – File Reader’, published by a company called ‘Hybrid Cars Simulator, Drift & Racing’ roughly two months ago and having amassed a significant following – some 50,000 people.
Until only recently, the app was clean, working as intended. Then, between June 24 and 30, it received an update that turned it into a banking trojan called Anatsa.
How to stay safe
This is a known piece of malware that’s been smuggled into the Play Store on multiple occasions in the past.
BleepingComputer claims in November 2021 researchers found a trojanized app with 300,000 downloads, and in June 2023 a separate one with 30,000 downloads. In February 2024 there was another app with Anatsa, counting 150,000 downloads, and in May the same year, two apps with 70,000 downloads between them.
Every time, Google removes the apps, but the attackers seem to find a way back.
Anatsa is a banking trojan that first scans the victim’s mobile device, looking for North American banking apps.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
If it finds any, it serves them an overlay that grabs credentials and other login data, granting the attackers the ability to log into accounts and make transactions. At the same time, the victims are presented with a message that the app is undergoing scheduled maintenance.
The app has now been removed from the Play Store, and if you have it installed, it would be wise to remove it and then run a full system scan using Play Protect. Resetting banking account credentials would also be advised.
“All of these identified malicious apps have been removed from Google Play,” a Google spokesperson told BleepingComputer. “Users are automatically protected by Google Play Protect, which can warn users or block apps known to exhibit malicious behavior on Android devices with Google Play Services.”
Via BleepingComputer
You might also like
Security researchers found a PDF app for Android sporting a banking trojan The trojan was introduced with a patch, six weeks after release It had more than 50,000 downloads, so users should beware A dangerous Android banking trojan has found a way to the Google Play Store once again, potentially…
Recent Posts
- This is the weirdest looking AI MAX+ 395 Mini PC that I’ve ever seen — and you can apparently hold it comfortably in the palm of your hand
- The Columbia hack is a much bigger deal than Mamdani’s college application
- One of My Favorite Gaming Laptops Gets a Serious Prime Day Cut
- Amazon’s best Kindles are cheaper than ever during Prime Day
- AMD is surpassing Nvidia in one particular market, and I don’t understand why — 11th eGPU based on AMD Radeon RX 7000 series debuts and even has Thunderbolt 5
Archives
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022