Google Play Apps Use Stealth Loaders to Deliver Anatsa Banking Malware
Brief
Android users are facing a fresh reminder that a familiar app-store listing can hide a financial threat.
Researchers have observed malicious loaders on Google Play that can prepare the ground for Anatsa, an Android banking Trojan designed to put account access at risk.
The campaign does not rely on an obvious malicious download at first. Instead, a seemingly useful app, including a trojanized PDF reader, shows a fake update prompt after it is opened.
The update then acts as the route for installing Anatsa. Analysts at Securelist identified the activity in their Q2 Android threat review.
Securelist said in a report shared with Cyber Security News (CSN) that the discovery included several loaders hosted directly through Google Play, a route users often regard as safer than unofficial sites.
The finding arrives as banking malware remains a major concern.
