Anatsa, also known as TeaBot, is an Android banking trojan first observed in 2020 that has become one of the more prominent mobile financial threats in the wild. It is designed to compromise Android devices and steal banking credentials and other sensitive financial data, while enabling operators to perform fraudulent transactions from the victim’s own device context. This on-device abuse helps the activity appear legitimate to financial institutions and can reduce the effectiveness of conventional fraud-detection controls.
Anatsa has repeatedly been distributed through trojanized Android applications masquerading as benign utilities, especially document readers, PDF viewers, and file-management apps, including apps published through Google Play. In observed campaigns, the initial application acted as a dropper or loader: it appeared functional or benign during review, then fetched the second-stage Anatsa payload after installation, sometimes under the pretense of a software update. This staged delivery model has been used to evade app-store screening and delay exposure of the malicious functionality.
Once active, Anatsa commonly abuses Android Accessibility Services and related high-risk permissions to monitor user activity, detect when targeted financial applications are opened, capture keystrokes, and interact with the device. It is known for overlay attacks in which fake login screens are displayed over legitimate banking or financial apps to harvest usernames, passwords, and other authentication data. Reported variants have also been associated with SMS access and interception capabilities, support for stealing session-related data, and the ability to facilitate unauthorized transactions against a large set of financial institutions worldwide, including banking, investment, and cryptocurrency services.
The malware incorporates multiple defense-evasion and anti-analysis measures. Reported samples have used obfuscation, runtime string decryption, encrypted command-and-control communications, emulator or sandbox checks, and staged payload concealment techniques intended to frustrate static and dynamic analysis. Some campaigns have shown selective payload activation and benign fallback behavior when analysis conditions are detected or when command infrastructure is unreachable.
Anatsa is widely tracked as a banking-focused Android malware family and has been repeatedly highlighted in campaigns targeting users across multiple regions, including Europe and North America. Its continued reappearance through trusted distribution channels and its mature overlay- and accessibility-based tradecraft make it a significant threat to mobile banking users and financial institutions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
the installer uses runtime string decryption powered by a dynamically generated DES key. The payload is hidden inside a corrupted ZIP archive with invalid compression and encryption flags, which causes most static analysis tools to fail completely.
the installer uses runtime string decryption powered by a dynamically generated DES key.
При запуске приложение показывало окно, запрашивающее «установку обновления», однако на самом деле таким образом на устройство загружался троянец.
To carry out these attacks, cybercriminals deploy phishing trojans and malicious apps designed to steal financial information and login credentials.
The trojan also runs a built-in keylogger that records everything the user types
These capabilities are used to capture user activity, steal banking credentials... These servers deliver fake banking login overlays that appear directly over legitimate banking apps, tricking users into entering their credentials on fraudulent pages...
These fake pages are downloaded fresh from the C2 server and are tailored to whichever financial app is found on the device.
He pointed to the Anatsa case from last year, an Android malware family used to drain bank accounts, where SI-CERT analyzed the residential proxy side.
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking malware delivered via trojanized apps on Google Play; it uses a fake update prompt to install the banking Trojan on victims’ devices.
Android banking trojan delivered via a malicious loader embedded in a Google Play PDF viewer app; the app displayed a fake update prompt that actually downloaded the trojan.
Android banking malware delivered via trojanized Google Play apps; it uses a fake update prompt to install the banking trojan on victims’ devices.
Android banking trojan that steals banking credentials, logs keystrokes, displays banking overlays, abuses accessibility and SMS permissions, downloads its payload from a remote server, and can carry out fraudulent transactions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.