Back to Newsroom
Threat Intel

Fake PDF Reader on Google Play Delivers Anatsa Banking Trojan

A document-reader app with more than 10,000 installs on Google Play has been caught dropping the Anatsa banking trojan, using a staged delivery trick to slip past Play Store review.

Fake PDF Reader on Google Play Delivers Anatsa Banking Trojan

Researchers have flagged an Android app posing as a PDF reader on Google Play as the latest delivery vehicle for Anatsa, a banking trojan also tracked as TeaBot. The app surpassed 10,000 installs before being identified, and like earlier Anatsa campaigns, it relied on a staged "dropper" model rather than shipping malicious code up front.

What happened

The app functioned as an ordinary document reader at first, which is enough to pass Google Play's initial review. Only after installation did it quietly pull down an additional component disguised as a routine update, and that second stage carried the Anatsa payload. This is the same pattern seen in an earlier Anatsa campaign in April that used a different decoy app before Google removed it; the installer and the banking payload in this latest wave again come from separate command-and-control infrastructure, which complicates tracing a single campaign end-to-end.

Anatsa's installer and payload stages have previously been shown to check a device for security tooling and sandboxing before unpacking further, and to use malformed archive headers and runtime encryption to make the payload harder to inspect. The current alert does not confirm which, if any, installations of this app actually proceeded to the banking-fraud stage, nor does it name specific banks targeted.

Why it matters

Anatsa's objective is Android banking fraud. Once active, it has been observed requesting SMS and accessibility permissions, contacting a command-and-control server, and checking the device for installed financial apps. When a targeted banking app is found, it can display a fake login overlay on top of the real app to harvest credentials, then use SMS access to intercept the one-time codes banks send to verify transactions. Because the dropper looks legitimate on install, standard app-store trust signals — install count, basic functionality, initial permission requests — are not a reliable guard on their own.

What to do

  • If you installed a PDF reader or similar utility app from Google Play that you don't fully trust, uninstall it and run a mobile security scan.
  • Treat unexpected requests for SMS or accessibility access from a utility app as a red flag, regardless of how the app is branded.
  • Keep Google Play Protect enabled, and watch your banking app for unusual login prompts or behavior.
  • If you notice unauthorized transactions, contact your bank immediately and change your credentials.
  • Security teams should add known indicators to monitoring, review network logs for matching domains and IPs, and confirm device-level context (install source, timing) before treating a match as a confirmed infection.
SHARE