By using this site, you agree privacy policies
Accept
Geek RoomGeek RoomGeek Room
  • Home
  • Tech
    TechShow More
    Split Technology Park welcomes first tenants: 26 MPSs and 6 startups
    October 31, 2024
    INNVEST Summit 2024: A premier event for innovation and economic competitiveness in the Western Balkans
    October 31, 2024
    Diaspora 4 Innovation: Kick-off event launches a new era for Albanian higher education
    October 31, 2024
    AI for good: Generative AI – Tirana chapter empowers Albanian Youth in tech innovation
    October 29, 2024
    Business Angel Summit 2024: Pioneering Investment and Startup Growth in Sarajevo
    October 29, 2024
  • Mobile
    MobileShow More
    Xiaomi 15 and 15 Pro set to launch on October 29: Official renders released
    October 24, 2024
    Dangerous virus infects millions of mobile phones through popular apps
    October 3, 2024
    The new iPhone 16 arrives in Croatia with a steep price tag
    September 26, 2024
    Beware of these phone numbers: Block them immediately to avoid scams
    September 11, 2024
    Beyond the brand: What really matters when buying a mobile phone
    September 5, 2024
  • Apps
    AppsShow More
    Shoppable widget by EmbedSocial: Revolutionizing E-commerce with authentic shopper content
    October 31, 2024
    Intel prevails in long-running legal battle against €1 billion EU fine
    October 31, 2024
    New definition of open source artificial intelligence released by OSI
    October 29, 2024
    CaSys introduces “Pay by Link” payment service for SMEs in Macedonia
    October 24, 2024
    Kickstarter surpasses $8 billion in donations across all projects
    October 17, 2024
  • Science
    ScienceShow More
    Sofia Tech Park: A thriving innovation hub for Southeast Europe
    October 29, 2024
    Breakthrough in prostate cancer treatment: Croatian scientists develop Vini, a tool to predict effective drug combinations
    October 24, 2024
    Digital Realty partners with Ecolab to pilot AI-powered water conservation solution
    October 24, 2024
    Sofia Tech Park to host the Southeast European Innovators Challenge Conference
    October 11, 2024
    ACG accelerates European growth with major expansion in Croatia
    October 9, 2024
  • Gaming
    GamingShow More
    “Windblown” – The new game from the creators of Dead Cells
    October 24, 2024
    Kraken Empire’s Journey and the creative brilliance of Toy Tactics
    October 21, 2024
    Serbian game studio Tricoman set to make a mark with their new RPG ‘Godforged’ on Steam
    October 16, 2024
    Release the demon with Kill Knight: A phenomenal combat experience with untapped potential
    October 14, 2024
    Nordeus launches new football game “Top Goal: Football Champion” in Serbia
    October 9, 2024
  • Cars
    CarsShow More
    Serbia signs strategic agreement with Hyundai Engineering for 1 GW of Solar Power
    October 16, 2024
    Stara Zagora: Poised to lead Bulgaria’s automotive revolution
    October 15, 2024
    Dacia unveils new Bigster: The flagship model for the C-SUV segment
    October 9, 2024
    Kineton Albania: Pioneering innovation in the automotive industry
    October 8, 2024
    Albania’s vehicle numbers surge in 2024: 73% of registered cars are over 15 years old
    August 20, 2024
  • Entertainment
    EntertainmentShow More
    Where are Generation Z’s famous tech entrepreneurs?
    October 29, 2024
    AllWeb offers special discounts for startups: A unique opportunity for networking and growth
    October 23, 2024
    Montenegro census reveals no ethnic majority, Montenegrins and Serbs nearly equal
    October 16, 2024
    “Primordial Passion” is the first luxury Albanian watch valued at €1.4 million by Argjendari Pirro
    October 15, 2024
    Albania takes the stage at BIG event Paris: Culture and innovation as economic drivers
    October 12, 2024
Search
Reading: Over 90 malicious Android apps with 5.5M installs found on Google Play
Notification Show More
Aa
Geek RoomGeek Room
Aa
  • Tech
  • Mobile
  • Apps
  • Science
  • Gaming
  • Cars
  • Entertainment
Search
  • Home
  • Tech
  • Mobile
  • Apps
  • Science
  • Gaming
  • Cars
  • Entertainment
Geek Room > Blog > Tech > Over 90 malicious Android apps with 5.5M installs found on Google Play
Tech

Over 90 malicious Android apps with 5.5M installs found on Google Play

Last updated: 2024/05/29 at 9:59 PM
Share
3 Min Read

Over 90 malicious Android apps were discovered on Google Play, amassing more than 5.5 million installations and delivering malware and adware, including a recent surge in the Anatsa banking trojan.Anatsa (also known as “Teabot”) is a banking trojan targeting over 650 applications of financial institutions across Europe, the US, the UK, and Asia. Its primary aim is to steal e-banking credentials for fraudulent transactions.

Contents
Anatsa’s evasion tacticsOther Google Play threatsHigh-risk malware

In February 2024, Threat Fabric reported that since late last year, Anatsa had infected at least 150,000 devices via Google Play through various decoy apps in the productivity software category. Recently, Zscaler reported that Anatsa has resurfaced on Android’s official app store, now distributed via two decoy applications: ‘PDF Reader & File Manager’ and ‘QR Reader & File Manager’. At the time of Zscaler’s analysis, the two apps had already accumulated 70,000 installations, highlighting the high risk of malicious dropper apps bypassing Google’s review process.

Anatsa’s evasion tactics

One of the techniques that help Anatsa dropper apps evade detection is a multi-stage payload loading mechanism involving four distinct steps:

  1. Dropper app retrieves configuration and essential strings from the C2 server.
  2. DEX file containing malicious dropper code is downloaded and activated on the device.
  3. Configuration file with Anatsa payload URL is downloaded.
  4. DEX file fetches and installs the malware payload (APK), completing the infection.

The DEX file also performs anti-analysis checks to ensure the malware won’t execute on sandboxes or emulating environments. Once Anatsa is operational on the newly infected device, it uploads the bot configuration and app scan results and then downloads the injections that match the victim’s location and profile.

Other Google Play threats

In the past couple of months, Zscaler discovered over 90 malicious applications on Google Play, collectively installed 5.5 million times. Most of these apps masqueraded as tools, personalization apps, photography utilities, productivity, and health & fitness apps. The five dominant malware families in these malicious apps are Joker, Facestealer, Anatsa, Coper, and various adware.

High-risk malware

While Anatsa and Coper only account for 3% of the total malicious downloads from Google Play, they are significantly more dangerous than others, capable of performing on-device fraud and stealing sensitive information. When installing new apps from Google Play, it’s crucial to review the requested permissions and decline those associated with high-risk activities such as Accessibility Service, SMS, and contacts list.

The researchers did not disclose the names of the 90+ apps or whether they had been reported to Google for takedown. However, at the time of writing, the two Anatsa dropper apps discovered by Zscaler have been removed from Google Play.

You Might Also Like

Split Technology Park welcomes first tenants: 26 MPSs and 6 startups

INNVEST Summit 2024: A premier event for innovation and economic competitiveness in the Western Balkans

Shoppable widget by EmbedSocial: Revolutionizing E-commerce with authentic shopper content

Intel prevails in long-running legal battle against €1 billion EU fine

Diaspora 4 Innovation: Kick-off event launches a new era for Albanian higher education

Share This Article
Facebook Whatsapp Whatsapp Copy Link
Previous Article OpenAI begins training GPT-5: What to expect from the next-generation AI model
Next Article Google defends its AI search after it told people to put glue on pizza

Social networks

Instagram Follow

Latest news

Split Technology Park welcomes first tenants: 26 MPSs and 6 startups
Tech October 31, 2024
INNVEST Summit 2024: A premier event for innovation and economic competitiveness in the Western Balkans
Tech October 31, 2024
Shoppable widget by EmbedSocial: Revolutionizing E-commerce with authentic shopper content
Apps October 31, 2024
Intel prevails in long-running legal battle against €1 billion EU fine
Apps October 31, 2024

Related articles

Tech

Split Technology Park welcomes first tenants: 26 MPSs and 6 startups

October 31, 2024
Tech

INNVEST Summit 2024: A premier event for innovation and economic competitiveness in the Western Balkans

October 31, 2024
Apps

Shoppable widget by EmbedSocial: Revolutionizing E-commerce with authentic shopper content

October 31, 2024
Apps

Intel prevails in long-running legal battle against €1 billion EU fine

October 31, 2024

About us

Geek Room is dedicated to technology and its enthusiasts through real-time information and videos about the latest innovations. Connect with our staff via email at: [email protected]
For cooperation opportunities, write to us at: [email protected]

Find us:

© 2023 Geekroom All Rights Reserved. Developed by MIMS
adbanner
AdBlock Detected
Our site is an advertising supported site. Please whitelist to support our site.
Okay, I'll Whitelist
Welcome Back!

Sign in to your account

Lost your password?