..Recently, we noticed an increase in instances of the Anatsa malware (a.k.a. TeaBot). This sophisticated malware employs dropper applications that appear benign to users, deceiving them into unwittingly installing the malicious payload. Once installed, Anatsa exfiltrates sensitive banking credentials and financial information from global financial applications. It achieves this through the use of overlay and accessibility techniques, allowing it to intercept and collect data discreetly…
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
An Android Banking Malware Active in the Google Play Store
Home » Forums » Cyber Security Information and Advisories » Cyber Security for Home Users » An Android Banking Malware Active in the Google Play Store
- This topic has 7 replies, 5 voices, and was last updated 11 months, 2 weeks ago.
Tags: Naya India
AuthorTopicAlex5723
AskWoody PlusMay 28, 2024 at 11:53 pm #2676099Viewing 2 reply threadsAuthorReplies-
Paul T
AskWoody MVPMay 29, 2024 at 12:15 am #2676106The malware comes as a 3rd party PDF/QR reader/file manager and uses a fake banking app front end that accepts your login credentials.
Bottom line: be careful what 3rd party apps you load on your phone.
cheers, Paul
3 users thanked author for this post.
-
Fred
AskWoody LoungerMay 29, 2024 at 1:59 am #2676120Bottom line: be careful what 3rd party apps you load on your phone.
Right you are….
Are the playstores for the apps losing their grip in what’s wrong?
Is there a way to check these “apps” yourself?.* _ ... _ * -
Paul T
AskWoody MVP -
n0ads
AskWoody LoungerMay 29, 2024 at 8:13 am #2676192The apps in the store are OK, the malware comes via an โupdateโ.
And therein lies the problem.
I recently experienced a situation where an app I’d been using for years was updated and it suddenly said it now needed to access basically everything on my phone in order to work; which is a very bad thing!
I checked and found the “updated” version had the same app ID as the original but was from a completely different source (I “assume” because the original owner was enticed to sell it.)
Needless to say, I removed it and installed a different app that provided most of the original app’s functionality; at least the parts I used.
A few days latter, I found out Google had removed the original app from their store because was scraping data from users phones and sending it to a 3rd party!
-
JC Zorkoff
AskWoody Plus -
n0ads
AskWoody LoungerMay 30, 2024 at 10:00 am #2676533This happened well over a year ago and I honestly don’t remember what it was called?
It was a clock widget that replaced the “default clock” with a bunch of different styles, some of which included the local weather conditions (temp & humidity) or the local forecast for the next week, depending on which clock style you chose.
I liked it because the time/weather info displayed without having to do anything other that just activate the phone screen.
The first clue that it’d been infected was when, after the update, it suddenly indicated it suddenly needed access to a lot of other apps on my phone (contacts, email, SMS, browser, etc. etc.) in addition to the original location only info!
-
-
-
-
Alex5723
AskWoody PlusMay 29, 2024 at 12:17 pm #2676263A few days latter, I found out Google had removed the original app from their store because was scraping data from users phones and sending it to a 3rd party!
Google want exclusive rights to scrap users data and sell to 3rd parties.
Viewing 2 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Difface : Reconstruction of 3D Human Facial Images from DNA Sequence
by
Alex5723
2 hours, 56 minutes ago -
Seven things we learned from WhatsApp vs. NSO Group spyware lawsuit
by
Alex5723
3 hours, 18 minutes ago -
Outdated Laptop
by
jdamkeene
8 hours, 21 minutes ago -
Updating Keepass2Android
by
CBFPD-Chief115
13 hours, 46 minutes ago -
Another big Microsoft layoff
by
Charlie
13 hours, 26 minutes ago -
PowerShell to detect NPU – Testers Needed
by
RetiredGeek
4 hours, 24 minutes ago -
May 2025 updates are out
by
Susan Bradley
13 hours, 51 minutes ago -
Windows 11 Insider Preview build 26200.5600 released to DEV
by
joep517
19 hours, 30 minutes ago -
Windows 11 Insider Preview build 26120.3964 (24H2) released to BETA
by
joep517
19 hours, 32 minutes ago -
Drivers suggested via Windows Update
by
Tex265
19 hours, 23 minutes ago -
Thunderbird release notes for 128 esr have disappeared
by
EricB
17 hours, 7 minutes ago -
CISA mutes own website, shifts routine cyber alerts to X, RSS, email
by
Nibbled To Death By Ducks
1 day, 2 hours ago -
Apple releases 18.5
by
Susan Bradley
20 hours, 47 minutes ago -
Fedora Linux 40 will go end of life for updates and support on 2025-05-13.
by
Alex5723
1 day, 3 hours ago -
How a new type of AI is helping police skirt facial recognition bans
by
Alex5723
1 day, 4 hours ago -
Windows 7 ISO /Windows 10 ISO
by
ECWS
11 hours, 42 minutes ago -
No HP software folders
by
fpefpe
1 day, 12 hours ago -
Which antivirus apps and VPNs are the most secure in 2025?
by
B. Livingston
9 hours, 26 minutes ago -
Stay connected anywhere
by
Peter Deegan
1 day, 17 hours ago -
Copilot, under the table
by
Will Fastie
1 day, 8 hours ago -
The Windows experience
by
Will Fastie
1 day, 23 hours ago -
A tale of two operating systems
by
Susan Bradley
3 hours, 57 minutes ago -
Microsoft : Resolving Blue Screen errors in Windows
by
Alex5723
2 days, 5 hours ago -
Where’s the cache today?
by
Up2you2
2 days, 20 hours ago -
Ascension says recent data breach affects over 430,000 patients
by
Nibbled To Death By Ducks
2 days, 13 hours ago -
Nintendo Switch 2 has a remote killing switch
by
Alex5723
1 day, 13 hours ago -
Blocking Search (on task bar) from going to web
by
HenryW
15 hours, 44 minutes ago -
Windows 10: Microsoft 365 Apps will be supported up to Oct. 10 2028
by
Alex5723
3 days, 13 hours ago -
Add or Remove “Ask Copilot” Context Menu in Windows 11 and 10
by
Alex5723
3 days, 13 hours ago -
regarding april update and may update
by
heybengbeng
3 days, 15 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.