Nefarious Anatsa Android Trojan caught stealing banking information and performing on-device fraud
December 14, 2025
  • Read Ecopy
  • Circulation
  • Advertise
  • Careers
  • About Us
  • Contact Us
Android AppiPhone AppArattai
Organiser
  • ‌
  • Bharat
    • Assam
    • Bihar
    • Chhattisgarh
    • Jharkhand
    • Maharashtra
    • View All States
  • World
    • Asia
    • Europe
    • North America
    • South America
    • Africa
    • Australia
  • Editorial
  • International
  • Opinion
  • RSS @ 100
  • More
    • Op Sindoor
    • Analysis
    • Sports
    • Defence
    • Politics
    • Business
    • Economy
    • Culture
    • Special Report
    • Sci & Tech
    • Entertainment
    • G20
    • Azadi Ka Amrit Mahotsav
    • Vocal4Local
    • Web Stories
    • Education
    • Employment
    • Books
    • Interviews
    • Travel
    • Law
    • Health
    • Obituary
  • Subscribe
    • Subscribe Print Edition
    • Subscribe Ecopy
    • Read Ecopy
  • ‌
  • Bharat
    • Assam
    • Bihar
    • Chhattisgarh
    • Jharkhand
    • Maharashtra
    • View All States
  • World
    • Asia
    • Europe
    • North America
    • South America
    • Africa
    • Australia
  • Editorial
  • International
  • Opinion
  • RSS @ 100
  • More
    • Op Sindoor
    • Analysis
    • Sports
    • Defence
    • Politics
    • Business
    • Economy
    • Culture
    • Special Report
    • Sci & Tech
    • Entertainment
    • G20
    • Azadi Ka Amrit Mahotsav
    • Vocal4Local
    • Web Stories
    • Education
    • Employment
    • Books
    • Interviews
    • Travel
    • Law
    • Health
    • Obituary
  • Subscribe
    • Subscribe Print Edition
    • Subscribe Ecopy
    • Read Ecopy
Organiser
  • Home
  • Bharat
  • World
  • Operation Sindoor
  • Editorial
  • Analysis
  • Opinion
  • Culture
  • Defence
  • International Edition
  • RSS @ 100
  • Magazine
  • Read Ecopy
Home World

Nefarious Anatsa Android Trojan caught stealing banking information and performing on-device fraud

As per the report, Anatsa Trojan is very dangerous because it can “bypass a wide array of existing fraud control mechanisms” as it has “very advanced Device-Takeover capabilities”.

WEBDESKWEBDESK
Jun 27, 2023, 10:00 pm IST
in World, Sci & Tech
Follow on Google News
FacebookTwitterWhatsAppTelegramEmail

Cyber fraud analysts at cyber security firm, ThreatFabric found an Android banking Trojan known as Anatsa on June 26. This malware steals the financial data of Android users when they download banking apps, which have over 30,000 downloads. This malware has affected several countries. ThreatFabric discovered the Anatsa Trojan two years ago, but it has emerged again lately.

Analysts discovered this android Trojan while monitoring multiple ongoing dropper campaigns happening at Google Play Store. As per Trend Micro, “Droppers are programs designed to extract other files from their own code. Typically, these programs extract several files into the computer to install a malicious program package”.

As per the report, Anatsa Trojan is very dangerous because it can “bypass a wide array of existing fraud control mechanisms” as it has “very advanced Device-Takeover capabilities”. This ongoing dropper campaign has affected around 600 banking applications in countries. The malware steals the information of the users of these inflected banking apps, such as credit card information, login credentials, PIN numbers etc. Then it initiates fraudulent transactions by performing Device-Takeover Fraud (DTO). The affected users are mainly from the UK, US, Germany, Austria, and Switzerland.

This Trojan is truly nefarious as it dupes users into downloading legitimate-looking banking apps. It also bypasses anti-fraud systems used by banks for the identification of automated, illegitimate transactions.

Cyber fraud analysts of ThreatFabric came to know about the emergence of Anatsa in March of this year. The analysts identified a dropper app on the Google Play Store, which was used to infect devices by pretending as a PDF reader application.

After installing such inflected apps, it would then “make a request to a page hosted on GitHub, where the dropper would get the URL to download the payload (also hosted on GitHub)”. These payloads disguise as an add-on to the original application.

When this app was reported, Google immediately pulled it down from the store, but after a month, it again got listed as a PDF viewer. The analysts discovered three more droppers in May and June.

As per the report by ThreatFabric, this latest Anatsa campaign reveals the threats faced by banks and financial institutions are evolving continuously. The only way to safeguard from this malware is to physically uninstall the app from the Android device.

Also Read: Beware! Delete these 101 applications to protect your Android phones from dangerous malware

It’s important to note that Android device has been facing continuous threats from cyber criminals through malware. Malware attacks planned by hackers are not new to the digital age, as we have witnessed them from time to time. Recently, a new Trojan malware called SpinOk was discovered, and reportedly it affected as many as 101 applications on Google Play Store.

Researchers have claimed that these malware attacks are in the form of advertisements and looks like a third-party attack. The motive of the hackers is to target the personal data of individuals. The malware or software module is equipped with spyware functionality. It can collect information on files stored on devices and is capable of transferring them to malicious actors. It can also substitute and upload clipboard contents to a remote server.

Also Read: Alert! ‘Daam’ virus infects Android phones, hacks into call records and change passwords: Govt

This month even Indian Computer Emergency Response Team or CERT-In released an advisory report stating that an Android malware named “Daam” infects mobile phones is spreading. This virus can access private information like call logs, contacts, history, and cameras. The advisory stated that the virus is capable of “bypassing anti-virus programs and deploying ransomware on the targeted devices”.

According to the CERT, the Android botnet is spread through third-party websites or apps downloaded from dubious or unknown sources. The advisory states, “Once it is placed in the device, the malware tries to bypass the security check of the device, and after a successful attempt, it attempts to steal sensitive data and permissions such as reading history and bookmarks, killing background processing, and reading call logs etc”.

Topics: Anatsa Android Trojandropper campaignsDevice-Takeover FraudDTObanking appsGoogle Play StoremalwareThreatFabricAnatsa TrojanAnatsa
ShareTweetSendShareSend
✮ Subscribe Organiser YouTube Channel. ✮
✮ Join Organiser's WhatsApp channel for Nationalist views beyond the news. ✮
Previous News

Anti-Sanatan people alleges President Droupadi Murmu kept away from idols in Jagannath temple, Delhi— Here’s the truth

Next News

Bamboo could be a future renewable energy source: Study

Related News

The accused, Labhshankar Maheshwari, had migrated from Pakistan and granted an Indian citizenship in 2005. (Photo: India.com)

Gujarat: Pakistani-origin man arrested for spying on Bharat after 17 years of having citizenship

Representative Image

Maya OS: Indian Defence Ministry to switch to indigenous operating system amid threats

Modi Government offers free tools to detect and remove malware, Read Details

(Photo Courtesy: The Economic Times)

MOVEit transfer tool leveraged by hackers to steal user data: US security researchers

A representation image, Source: Cyber Security News

Beware! Delete these 101 applications to protect your Android phones from dangerous malware

Alert! ‘Daam’ virus infects Android phones, hacks into call records and change passwords: Govt

Load More

Comments

The comments posted here/below/in the given space are not on behalf of Organiser. The person posting the comment will be in sole ownership of its responsibility. According to the central government's IT rules, obscene or offensive statement made against a person, religion, community or nation is a punishable offense, and legal action would be taken against people who indulge in such activities.

Latest News

The rise of right-wing in the contemporary world

The resurgence of nationalist ideologies in contemporary world politics

J&K LG Manoj Sinha

J&K: LG Sinha lauds SKIMS staff in providing top medicare to people, improvement in medical infrastructure post-2019

More than 5 lakh people came together to chant Bhagwad Gita

Kolkata’s Chorus of the Gita: Five lakh voices, one eternal message

Representative Image

MUDA Scam in Karnataka: ED probe reveals former commissioner took Rs 22.47 crore bribe for illegal plot allotments

NCERT introduces Vasudhaiva Kutumbakam chapter in Class 7

NCERT introduces Vasudhaiva Kutumbakam chapter in Class 7 social science curriculum

US lawmakers warn Trump towards irrational tariffs on India

Trump tariffs on India mounts pressure on American workers & consumers; US lawmakers move resolution to repeal tariffs

Representative image

SIR in West Bengal: Election Commission to reverify over one crore entries after discovering anomalies

Official logo of Magh Mela 2026

Magh Mela 2026: CM Yogi Adityanath unveils logo depicting confluence of Ganga-Yamuna, Saraswati & 14 phases of moon

Draft SOP prepared for inventory of Ratna Bhandar at Puri Jagannath Temple by SJTA Niti Sub-Committee

Odisha: Draft SOP prepared for inventory of Ratna Bhandar at Puri Jagannath Temple; Approval process underway

Sheikh Mujibur Rahman

Superficial bonhomie between Bangladesh & Pakistan set to break: Rawalpindi labels Sheikh Mujibur Rahman as ‘traitor’

Load More
  • Privacy
  • Terms
  • Cookie Policy
  • Refund and Cancellation
  • Delivery and Shipping

© Bharat Prakashan (Delhi) Limited.
Tech-enabled by Ananthapuri Technologies

  • Home
  • Search Organiser
  • Bharat
    • Assam
    • Bihar
    • Chhattisgarh
    • Jharkhand
    • Maharashtra
    • View All States
  • World
    • Asia
    • Africa
    • North America
    • South America
    • Europe
    • Australia
  • Editorial
  • Operation Sindoor
  • Opinion
  • Analysis
  • Defence
  • Culture
  • Sports
  • Business
  • RSS @ 100
  • Entertainment
  • More ..
    • Sci & Tech
    • Vocal4Local
    • Special Report
    • Education
    • Employment
    • Books
    • Interviews
    • Travel
    • Health
    • Politics
    • Law
    • Economy
    • Obituary
  • Subscribe Magazine
  • Read Ecopy
  • Advertise
  • Circulation
  • Careers
  • About Us
  • Contact Us
  • Policies & Terms
    • Privacy Policy
    • Cookie Policy
    • Refund and Cancellation
    • Terms of Use

© Bharat Prakashan (Delhi) Limited.
Tech-enabled by Ananthapuri Technologies