Anatsa, also known as TeaBot and Toddler, is an Android banking trojan first identified in 2021. It targets banking, investment, and cryptocurrency applications through credential-harvesting overlays, keylogging, and abuse of Android Accessibility Services. Accessibility access enables the malware to collect visible UI content, monitor user activity, interact with interface elements, manipulate text input, and support remote device control for on-device fraud. It can also collect contacts and device information, steal Google Authenticator codes, and interfere with removal or device shutdown.
Anatsa has been distributed through smishing campaigns using parcel-delivery lures and through trojanized utility applications, including document readers, QR scanners, and cryptocurrency tools published on Google Play. These applications commonly use staged delivery: an initially benign-looking loader presents a fraudulent in-app update prompt, selectively retrieves the payload after installation, and requests installation and Accessibility privileges. The malware employs anti-analysis and obfuscation measures, including device profiling, runtime decryption, and conditional payload delivery. Campaigns have targeted financial institutions internationally, including European banking applications, and enable operators to conduct fraudulent transactions directly from compromised devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Anatsa was discovered by ThreatFabric in January 2021. Anatsa is a rather advanced Android banking trojan with RAT and semi-ATS capabilities.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
decrypts the malicious payload file called eepHM.json from the app’s assets folder to an executable dex format named ‘eepHM.odex’ and loads the decrypted file
These apps posed as QR code scanners, PDF scanners, and cryptocurrency apps.
This malware also terminates the predefined list of apps process(es)... that list includes a few popular security products... in order to remain undetected.
this malicious apk decrypts the malicious payload file called kbu.json from the app’s assets folder to an executable dex format named ‘kbu.odex’ and loads the decrypted file
the configuration contains filter rules based on device model. Based on the models being filtered out and the code of the dropper, we can draw a conclusion that this is done to avoid downloading the payload on emulators or research environment.
This is a classic Android bot, equipped with credential stealing capabilities such as the use of overlays (fake login screens) for crypto-currency wallet apps and Android banking apps.
Other features include keylogging, contact information and device information exfiltration, and accessibility logging.
the malware C2 sends the specific payload(s) to the victim device to perform an overlay attack and track all the activity related to the identified targeted application(s).
This is a classic Android bot, equipped with credential stealing capabilities such as the use of overlays (fake login screens) for crypto-currency wallet apps and Android banking apps.
Other features include keylogging, contact information and device information exfiltration, and accessibility logging.
The PTI team has de-anonymized the C&C server and discovered that Toddler has already infected more than 7,632 devices at the time of this report.
it's also designed to retrieve a malicious APK file hosted on GitHub
39 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan that targets financial applications to steal cryptocurrency assets and money.
Android banking trojan delivered via malicious Google Play loader apps using fake update prompts; once installed, it seeks information that can help criminals access financial accounts or approve fraudulent activity.
Android banking malware delivered via trojanized apps on Google Play; it uses a fake update prompt to install the banking Trojan on victims’ devices.
Android banking trojan delivered via a malicious loader embedded in a Google Play PDF viewer app; the app displayed a fake update prompt that actually downloaded the trojan.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.