This evil Android trojan is targeting hundreds of banking apps to spread money-stealing malware

Play Store
(Image credit: senengmotret / Shutterstock.com)

Banking Trojan Anatsa is behind multiple confirmed fraud cases from Android apps sold on the Google Play Store, according to cybersecurity company ThreatFabric.

With over 30,000 installations, ThreatFabric says that the campaign’s target list contains almost 600 financial applications from all over the world, and its most recent attacks have been centered around the US, the US, Germany, Austria, and Switzerland.

By stealing credentials used to authenticate mobile banking customers and then performing Device-Takeover Fraud, the threat actor has been carrying out fraudulent transactions since Anatsa’s discovery in 2020.

Watch out for this mobile banking malware

Based on the number of targeted applications per country, the US tops the charts. Italy, Germany, the UK, and France round off the top five, and the UAE, Switzerland, South Korea, Australia, and Sweden complete the top 10.

In less than a year, ThreatFabric has added a further 90 applications that have been targeted to spread the money-stealing malware, but don’t be fooled: you don’t need to be downloading a banking app to be affected.

Because people typically have their guard up when it comes to online banking, many of the malware droppers identified by the cybersecurity researchers have posed as PDF viewers. Having informed the Play Store of its findings, ThreatFabric found Google quick to react, but the threat actors just as quick to republish apps of a similar nature.

Sensitive information like credentials, credit card details, balance, and payment information is collected from the infected device. The threat actor then goes on to exfiltrate money through cryptocurrencies and local mules in a Device Takeover attack, which has so far proven challenging for banking anti-fraud systems to catch.

Referring to an evolving threat landscape that baking institutions are having to deal with, Internet users are being urged to remain vigilant when it comes to sharing details with third parties online, including following ads to download apps and content.

A Google spokesperson has confirmed to TechRadar Pro in an email:

"All of these identified malicious apps have been removed from Google Play and the developers have been banned. Google Play Protect also protects users by automatically removing apps known to contain this malware on Android devices with Google Play Services."

TOPICS
Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
Malware worm
Coordinated global mobile malware campaign targets banking apps and cryptocurrency platforms
mobile phone
Popular Android financial help app is actually dangerous malware
An Android phone being held in the hand
These malicious Android apps were installed over 60 million times - here's how to stay safe
A close-up photo of an iPhone, with the App Store icon prominent in the center of the image.
App stores are increasingly becoming a major security worry
Android phone malware
Screen reading malware found in iOS app stores for first time - and it might steal your cryptocurrency
Android phone malware
This nasty Android malware is posing as the Telegram Premium app
Latest in Pro
Branch office chairs next to a TechRadar-branded badge that reads Big Savings.
This office chair deal wins the Amazon Spring Sale for me and it's so good I don't expect it to last
Saily eSIM by Nord Security
"Much more than just an eSIM service" - I spoke to the CEO of Saily about the future of travel and its impact on secure eSIM technology
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business
FlexiSpot office furniture next to a TechRadar-branded badge that reads Big Savings.
Upgrade your home office for under $500 in the Amazon Spring Sale: My top picks and biggest savings
Beelink EQi 12 mini PC
I’ve never seen a PC with an Intel Core i3 CPU, 24GB RAM, 500GB SSD and two Gb LAN ports sell for so cheap
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring