Over 90 malicious Android apps were discovered on Google Play, collectively installed 5.5 million times, delivering malware and adware. These apps included the Anatsa banking trojan, which targets financial apps to steal credentials. Recently, Anatsa resurfaced in Google Play via decoy apps like 'PDF Reader & File Manager' and 'QR Reader & File Manager', together amassing 70,000 installs. Despite Google's review process, these apps utilized a sophisticated multi-stage mechanism to evade detection and deploy malware, highlighting ongoing security challenges.
At the time of Zscaler's analysis, the two decoy applications, 'PDF Reader & File Manager' and 'QR Reader & File Manager,' had amassed 70,000 installations1.
According to Threat Fabric's report in February 2024, Anatsa had achieved at least 150,000 infections via Google Play since its resurgence in late 2023. The banking trojan has been targeting users in Europe, the US, the UK, and Asia through malware droppers hosted on Google Play1.