Malicious Document Reader App on Google Play Infects Users with Anatsa Trojan
Article Content
- •A fake document reader app on Google Play installed the Anatsa banking trojan.
- •The app was downloaded over 10,000 times before being removed by Google.
- •Users are at risk of financial fraud and credential theft due to the malware.
A fake document reader app on the Google Play Store has been discovered to install the Anatsa banking trojan on Android devices. The app, which was downloaded over 10,000 times before its removal, poses a significant risk to users by enabling financial fraud and credential theft. Anatsa is known for its capability to siphon sensitive information from infected devices. The malicious app was available on the official marketplace, illustrating vulnerabilities in app vetting processes. Users who downloaded the app may have already been compromised, leading to potential financial losses. Google has since removed the app, but the impact on users remains a concern. Security experts advise users to be cautious of apps that request excessive permissions. The incident underscores the need for improved security measures in app marketplaces.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Anatsa in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Spyware Scam Targets Indeed Users with Fake Interview Apps Cybercriminals are targeting job seekers on Indeed by promoting fake interview apps that install malware on Android devices. Malwarebytes reported that users are tricked into downloading a malicious APK file named 'MyInterview' after responding to fake job offers. The apps mimic the Indeed login page and, once…
AI Manipulation Campaigns Exploit Indirect Prompt Injection Techniques Zscaler's ThreatLabz identified two campaigns using indirect prompt injection (IPI) to manipulate AI agents into executing fraudulent actions. The first campaign involves a payment scam disguised as API documentation, tricking AI agents into sending funds to attacker-controlled accounts. The second campaign employs a…