Dangerous Android malware targets US banking apps – 50,000 people already affected, make sure you’re not next
- Security researchers found a PDF app for Android sporting a banking trojan
- The trojan was introduced with a patch, six weeks after release
- It had more than 50,000 downloads, so users should beware
A dangerous Android banking trojan has found a way to the Google Play Store once again, potentially affecting tens of thousands of North American users, experts have warned.
Security researchers from Threat Fabric found an app on the Play Store, called ‘Document Viewer – File Reader’, published by a company called ‘Hybrid Cars Simulator, Drift & Racing’ roughly two months ago and having amassed a significant following – some 50,000 people.
Until only recently, the app was clean, working as intended. Then, between June 24 and 30, it received an update that turned it into a banking trojan called Anatsa.
How to stay safe
This is a known piece of malware that’s been smuggled into the Play Store on multiple occasions in the past.
BleepingComputer claims in November 2021 researchers found a trojanized app with 300,000 downloads, and in June 2023 a separate one with 30,000 downloads. In February 2024 there was another app with Anatsa, counting 150,000 downloads, and in May the same year, two apps with 70,000 downloads between them.
Every time, Google removes the apps, but the attackers seem to find a way back.
Anatsa is a banking trojan that first scans the victim’s mobile device, looking for North American banking apps.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
If it finds any, it serves them an overlay that grabs credentials and other login data, granting the attackers the ability to log into accounts and make transactions. At the same time, the victims are presented with a message that the app is undergoing scheduled maintenance.
The app has now been removed from the Play Store, and if you have it installed, it would be wise to remove it and then run a full system scan using Play Protect. Resetting banking account credentials would also be advised.
“All of these identified malicious apps have been removed from Google Play,” a Google spokesperson told BleepingComputer. “Users are automatically protected by Google Play Protect, which can warn users or block apps known to exhibit malicious behavior on Android devices with Google Play Services.”
Via BleepingComputer
You might also like
Security researchers found a PDF app for Android sporting a banking trojan The trojan was introduced with a patch, six weeks after release It had more than 50,000 downloads, so users should beware A dangerous Android banking trojan has found a way to the Google Play Store once again, potentially…
Recent Posts
- Best Buy slashes up to $400 off Apple tech in a limited-time sale — get AirPods, MacBooks, iPads and Apple Watches from $99.99
- The Instagram Plus subscription has officially launched
- Cyberdecks used to look like little laptops, but now they’re getting more personal
- Canada Prime Minister Mark Carney announces questionable national AI strategy
- Kevin O’Leary agrees to downsize massive Utah data center
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023