Mobile device owners running Android are being alerted to a fraudulent application on Google’s official marketplace that is being leveraged to distribute harmful software onto phones without users’ knowledge.
The dangerous programme poses as a document viewer and has been installed on over one hundred thousand occasions.
Following installation, it covertly introduces the Anatsa banking trojan onto the Android device.
According to Zimperium, people are tricked into downloading applications that appear innocuous and claim to handle or view documents.
Instead, it deploys harmful code able to extract private information, obtain login details, and retain ongoing access to the device.
Financial crime currently represents forty-five percent of all criminal activity recorded in England and Wales. This figure illustrates what this signifies for corporate fraud prevention, security professionals and compliance officers, along with the fresh regulatory duties this creates for organisations.
The bogus programme evaded Google’s automatic protection mechanisms and was discovered to still be available on the marketplace despite security experts raising concerns.
How the Anatsa banking trojan operates
The Anatsa trojan is engineered to obtain sensitive monetary information and empty victims’ accounts by assuming control of their handsets.
The programme employs a multi-phase contamination approach to sidestep early identification, according to Cyber Press.
The outlet reported that when someone installs the counterfeit document reader, the software initially behaves as expected, presenting the anticipated screens to prevent suspicion.
However, concealed from view, the programme establishes a connection to an external server to retrieve the secondary harmful component.
Once the Anatsa component is placed on the victim’s device, it promptly seeks extensive permissions, specifically focusing on Android’s Accessibility Services.
By obtaining these elevated rights, the harmful software can:
Monitor what appears on the user’s display
Log every keystroke
Operate elements of the device’s interface
The main purpose of the Anatsa trojan is to surveil banking and money-related applications.
Cyber Press added that when a victim tries to access a targeted banking application, Anatsa interrupts the login procedure and presents a false screen that precisely replicates the genuine authentication page.
Unaware users input their security details into this counterfeit form, thereby providing their usernames, passwords and two-factor authentication codes straight to the criminals.
The harmful programme can also retrieve text messages and authorise payment requests.
Identifying potentially dangerous applications to steer clear of the Anatsa trojan
Android users who may have installed any questionable document viewing applications recently should promptly check their downloaded programmes and review their financial statements for any unrecognised transactions.
