🚨 Another campaign with the Anatsa banking trojan has surfaced.
Kaspersky researchers found a malicious app on Google Play, downloaded 10K times before being removed, used to deliver the banking trojan. A user downloads a seemingly harmless PDF reader app, opens it and sees a prompt to update. If the ‘update’ button is hit, a banking trojan gets installed that would spy on the user to steal funds.
Both the dropper and the trojan itself are detected by Kaspersky, IOCs below:
Dropper:
5c9b09819b196970a867b1d459f9053da38a6a2721f21264324e0a8ffef01e20
C2: 23.251.108[.]10
Payload (Anatsa/TeaBot): c96b80bbdece972ff7ea7b5ef868b64e88a5ff880cda15f88b88a447515dc060
C2: 172.86.91[.]94