TeaBot, also known as Anatsa and Toddler, is an Android banking trojan first identified in early 2021. It targets banking customers and has expanded its application targeting to financial institutions, cryptocurrency services, digital wallets, and insurance applications across Europe, North America, and other regions. TeaBot steals banking credentials, SMS messages, and authentication codes; enumerates installed applications; captures screenshots; and uses Android Accessibility Services for targeted keylogging, screen interaction, gesture simulation, and remote on-device fraud. It deploys application-specific overlay injections when targeted financial applications are detected, enabling credential capture and account takeover. TeaBot can also obtain authenticator codes, conceal itself by removing its launcher icon, mute the device, disable Google Play Protect, terminate selected processes including security products, and run background services. It uses staged loading of executable Android code, code obfuscation, and partially encrypted command-and-control communications to hinder analysis. TeaBot has been distributed through smishing campaigns impersonating media, delivery, and logistics services, as well as through trojanized Google Play utility applications that use deceptive update prompts to induce sideloading of the final payload and granting of Accessibility permissions. It has also been delivered by Android malware droppers and, at times, through FluBot distribution infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Reports suggest that hackers have used the Google Play store to distribute the “dropper applications”.
They have an arsenal of other commands available, including sending an SMS with content provided by the command and control (CnC).
The app itself presents a fake UI saying that an update is required, and users are instructed to allow the Android app to install third-party packages.
Once the victims install and open the app through the Google Play store, the app gives a pop-up message that an update must be installed. When victims click on install, the application downloads the dropper and installs another application on the victim’s device.
A full detailed report on how threat Actors used strong obfuscation techniques to evade antivirus software was published by Cleafy.
In August 2021, they matched a voicemail theme by resembling messages that network carriers send on missed calls. This changed in September 2021 when SMS texts started to abuse the DHL brand.
This malware also terminates the predefined list of apps process(es)... that list includes a few popular security products... in order to remain undetected.
this malicious apk decrypts the malicious payload file called kbu.json from the app’s assets folder to an executable dex format named ‘kbu.odex’ and loads the decrypted file
When the user starts the Android app, it also starts a background service that checks the country code of the current registered operator... If the country starts with a 'U' or is unavailable, the app skips executing the malicious code.
The malicious code within the app has a minimal footprint, as the authors were careful about not triggering security heuristics.
This permission is acquired to view and control the screen on the victim’s device which is used for obtaining login credentials, 2FA codes, and to read SMS.
Abusing the Android Accessibility Service, this Trojan acts as a keylogger to steal all the victim’s information on the device.
the malware C2 sends the specific payload(s) to the victim device to perform an overlay attack and track all the activity related to the identified targeted application(s).
This permission is acquired to view and control the screen on the victim’s device which is used for obtaining login credentials, 2FA codes, and to read SMS.
Abusing the Android Accessibility Service, this Trojan acts as a keylogger to steal all the victim’s information on the device.
The PTI team has de-anonymized the C&C server and discovered that Toddler has already infected more than 7,632 devices at the time of this report.
By analyzing TeaBot network communications, it was possible to group them into the following three main types: [C2-URL]/api/botupdate ... [C2-URL]/api/getkeyloggers ... [C2-URL]/api/getbotinjects
A message instructs the target to download a third-party application by clicking a download button. As of September 2021, these downloads are either Flubot or in some cases Teabot.
91 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mobile banking malware focused on device takeover and session manipulation to bypass strong authentication controls; heavily targets North America.
Referenced as another notorious Android banking malware family.
Android banking trojan delivered by DawDropper; the article notes its payload was hosted on GitHub and contrasts its delivery method with DawDropper’s Firebase-based approach.
Another Android banking malware family that was distributed through Flubot smishing infrastructure instead of Flubot in some campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.