Anatsa, also known as TeaBot, is an Android banking trojan active since early 2021. It is designed to steal banking credentials, SMS messages, and other sensitive data from infected devices, and to facilitate on-device fraud against financial applications. The malware abuses Android Accessibility Services to observe screen content, simulate user interaction, capture credentials and one-time codes, perform keylogging against targeted applications, and execute overlay attacks when selected banking or financial apps are opened. Reported functionality also includes screenshot or screen-stream capture, account and authenticator-code theft, device muting, application removal, disabling security protections such as Google Play Protect, and hiding its launcher icon to reduce user awareness.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Reports suggest that hackers have used the Google Play store to distribute the “dropper applications”.
They have an arsenal of other commands available, including sending an SMS with content provided by the command and control (CnC).
The app itself presents a fake UI saying that an update is required, and users are instructed to allow the Android app to install third-party packages.
Once the victims install and open the app through the Google Play store, the app gives a pop-up message that an update must be installed. When victims click on install, the application downloads the dropper and installs another application on the victim’s device.
A full detailed report on how threat Actors used strong obfuscation techniques to evade antivirus software was published by Cleafy.
In August 2021, they matched a voicemail theme by resembling messages that network carriers send on missed calls. This changed in September 2021 when SMS texts started to abuse the DHL brand.
This malware also terminates the predefined list of apps process(es)... that list includes a few popular security products... in order to remain undetected.
this malicious apk decrypts the malicious payload file called kbu.json from the app’s assets folder to an executable dex format named ‘kbu.odex’ and loads the decrypted file
When the user starts the Android app, it also starts a background service that checks the country code of the current registered operator... If the country starts with a 'U' or is unavailable, the app skips executing the malicious code.
The malicious code within the app has a minimal footprint, as the authors were careful about not triggering security heuristics.
This permission is acquired to view and control the screen on the victim’s device which is used for obtaining login credentials, 2FA codes, and to read SMS.
Abusing the Android Accessibility Service, this Trojan acts as a keylogger to steal all the victim’s information on the device.
This permission is acquired to view and control the screen on the victim’s device which is used for obtaining login credentials, 2FA codes, and to read SMS.
Abusing the Android Accessibility Service, this Trojan acts as a keylogger to steal all the victim’s information on the device.
The PTI team has de-anonymized the C&C server and discovered that Toddler has already infected more than 7,632 devices at the time of this report.
By analyzing TeaBot network communications, it was possible to group them into the following three main types: [C2-URL]/api/botupdate ... [C2-URL]/api/getkeyloggers ... [C2-URL]/api/getbotinjects
A message instructs the target to download a third-party application by clicking a download button. As of September 2021, these downloads are either Flubot or in some cases Teabot.
91 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another notorious Android banking malware family.
Android banking trojan delivered by DawDropper; the article notes its payload was hosted on GitHub and contrasts its delivery method with DawDropper’s Firebase-based approach.
Another Android banking malware family that was distributed through Flubot smishing infrastructure instead of Flubot in some campaigns.
Mentioned as another banking trojan that abuses Android Accessibility APIs, for comparison with MaliBot.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.