Close Menu
  • Homepage
  • Local News
  • India
  • World
  • Politics
  • Sports
  • Finance
  • Entertainment
  • Business
  • Technology
  • Health
  • Lifestyle
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA
Facebook X (Twitter) Instagram Pinterest
JHB NewsJHB News
  • Local
  • India
  • World
  • Politics
  • Sports
  • Finance
  • Entertainment
Let’s Fight Corruption
JHB NewsJHB News
Home»Technology»Anatsa banking Trojan reappeared through apps on Google Play
Technology

Anatsa banking Trojan reappeared through apps on Google Play

February 20, 2024No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
AH TechDeals 300x150
Share
Facebook Twitter LinkedIn Pinterest Email

The resurgence of the Anatsa banking Trojan has sparked considerations amongst cybersecurity specialists because it targets European monetary establishments, posing a major menace to cellular banking safety. Over the previous 4 months, the Anatsa marketing campaign has exhibited a dynamic evolution, with 5 distinct waves focusing on particular areas, together with Slovakia, Slovenia, and Czechia, along with earlier targets just like the UK, Germany, and Spain.

Fraud detection firm ThreatFabric detected a resurgence of the Anatsa banking Trojan in November 2023

The newest iteration of the Anatsa marketing campaign, detected by ThreatFabric, demonstrates a complicated modus operandi. It employed a number of techniques to infiltrate cellular gadgets and execute malicious actions. Regardless of enhanced detection and safety mechanisms on Google Play, Anatsa droppers have efficiently exploited AccessibilityService. It enabled them to automate the set up of payloads.

One notable facet of the current Anatsa marketing campaign is using manufacturer-specific code focusing on Samsung gadgets. This tailor-made method suggests a strategic adaptation by menace actors to maximise the impression of their malware. Whereas the marketing campaign straight impacted Samsung customers on this section, the specter of related techniques focusing on different machine producers stays a priority.

Anatsa marketing campaign has successfully bypassed AccessibilityService restrictions imposed by Android 13

Moreover, the Anatsa marketing campaign has successfully bypassed restrictions imposed by Android 13, enabling droppers to put in payloads whereas evading detection. This system, coupled with dynamically loaded DEX recordsdata, enhances the malware’s stealth capabilities. It poses challenges for safety engines and will increase the chance of profitable infections.

The potential for machine takeover by a trojan horse poses a extreme menace, with every set up rising the chance of fraudulent exercise and unauthorized entry to delicate data.

Beeping Pc has famous 5 functions which might be linked to the Anatsa marketing campaign. These embrace Telephone Cleaner – File Explorer (com.volabs.androidcleaner), PDF Viewer – File Explorer (com.xolab.fileexplorer), PDF Reader – Viewer & Editor (com.jumbodub.fileexplorerpdfviewer), Telephone Cleaner: File Explorer (com.appiclouds.phonecleaner), and PDF Reader: File Supervisor (com.tragisoap.fileandpdfmanager).

Google has responded to the matter

A Google spokesperson has knowledgeable BeepingComputer that Google Play has eliminated all the 5 apps related to this marketing campaign. He added that Google Play Shield already protects Android gadgets in opposition to recognized variations of this malware. That is on by default on Android gadgets with Google Play Companies.

Anatsa banking trojan payload fetchAnatsa banking trojan payload fetch
Picture: ThreatFabric

Source link

Anatsa apps banking Google play reappeared Trojan
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Microsoft says ungoverned AI agents could become corporate 'double agents.' Its fix costs $99 a month.

March 9, 2026

‘AI brain fry’: Managing AI tools is mentally draining workers who want to quit, new study warns | Technology News

March 9, 2026

Apple iPad Air (2026) Review: More Power, Same Formula

March 9, 2026

Australians reach for VPNs, find porn sites blocked as online age-restrictions take effect | Technology News

March 9, 2026
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

There’s another energy market that may get hit harder than oil by Strait of Hormuz closure

March 10, 2026

Family of Teacher Killed in Prank Wants Charges Against Teens Dropped

March 9, 2026

Microsoft says ungoverned AI agents could become corporate 'double agents.' Its fix costs $99 a month.

March 9, 2026

Agilent Technologies to acquire Biocare Medical in $950m deal

March 9, 2026
Popular Post

Fallout TV Series News, Trailer, Plot And Release Date

What is nutritional yeast?

Jim Ratcliffe acquires 25% stake, becomes minority shareholder of Manchester United | Football News

Subscribe to Updates

Get the latest news from JHB News about Bangalore, Worlds, Entertainment and more.

JHB News
Facebook X (Twitter) Instagram Pinterest
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA
© 2026 Jhb.news - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.