Skip to content
ThreatCluster

Malicious Document Reader App on Google Play Infects Users with Anatsa Trojan

First seen 28 Apr 2026, 06:34 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster April 29, 2026 at 03:43 UTC
  • A fake document reader app on Google Play installed the Anatsa banking trojan.
  • The app was downloaded over 10,000 times before being removed by Google.
  • Users are at risk of financial fraud and credential theft due to the malware.

A fake document reader app on the Google Play Store has been discovered to install the Anatsa banking trojan on Android devices. The app, which was downloaded over 10,000 times before its removal, poses a significant risk to users by enabling financial fraud and credential theft. Anatsa is known for its capability to siphon sensitive information from infected devices. The malicious app was available on the official marketplace, illustrating vulnerabilities in app vetting processes. Users who downloaded the app may have already been compromised, leading to potential financial losses. Google has since removed the app, but the impact on users remains a concern. Security experts advise users to be cautious of apps that request excessive permissions. The incident underscores the need for improved security measures in app marketplaces.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 134d ago How this analysis works

Timeline

2026-04-28
Malicious document reader app discovered on Google Play.
2026-04-28
App removed after surpassing 10,000 downloads.

More articles in this cluster (2)

Following this threat?

Track Anatsa in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed