Bitcoin Forum
October 17, 2025, 04:31:00 AM *
News: Latest Bitcoin Core release: 30.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [Read]: Anatsa Banking Trojan spreads thru Fake PDF download  (Read 98 times)
btc_angela (OP)
Hero Member
*****
Offline Offline

Activity: 3080
Merit: 620



View Profile
July 10, 2025, 07:52:06 AM
Merited by Cricktor (2), TravelMug (1)
 #1

There is a new banking trojan known as Anatsa as it steals users information and other keylogging attacks. And why it should concern us crypto users? It's because some of us might have stored a lot of information as well together with our banking info and so it's a shooting two birds with one stone.

And so there is a chance that it might evolved into a full blown malware to target crypto wallets and everything related to it. So this is just a fair warning to everyone.

Sample download on Google Play:



And probably another look that we shouldn't blindly trust anything what we see on the Big G.

https://www.threatfabric.com/blogs/anatsa-targets-north-america-uses-proven-mobile-campaign-process



▄▄█████████████████▄▄
▄█████████████████████▄
███▀▀█████▀▀░░▀▀███████

██▄░░▀▀░░▄▄██▄░░█████
█████░░░████████░░█████
████▌░▄░░█████▀░░██████
███▌░▐█▌░░▀▀▀▀░░▄██████
███░░▌██░░▄░░▄█████████
███▌░▀▄▀░░█▄░░█████████
████▄░░░▄███▄░░▀▀█▀▀███
██████████████▄▄░░░▄███
▀█████████████████████▀
▀▀█████████████████▀▀
..Rainbet.com..
CRYPTO CASINO & SPORTSBOOK
|
█▄█▄█▄███████▄█▄█▄█
███████████████████
███████████████████
███████████████████
█████▀█▀▀▄▄▄▀██████
█████▀▄▀████░██████
█████░██░█▀▄███████
████▄▀▀▄▄▀███████
█████████▄▀▄██
█████████████████
███████████████████
██████████████████
███████████████████
 
 $20,000 
WEEKLY RAFFLE
|



█████████
█████████ ██
▄▄█░▄░▄█▄░▄░█▄▄
▀██░▐█████▌░██▀
▄█▄░▀▀▀▀▀░▄█▄
▀▀▀█▄▄░▄▄█▀▀▀
▀█▀░▀█▀
10K
WEEKLY
RACE
100K
MONTHLY
RACE
|

██









█████
███████
███████
█▄
██████
████▄▄
█████████████▄
███████████████▄
░▄████████████████▄
▄██████████████████▄
███████████████▀████
██████████▀██████████
██████████████████
░█████████████████▀
░░▀███████████████▀
████▀▀███
███████▀▀
████████████████████   ██
 
..►PLAY...
 
████████   ██████████████
Sanitough
Hero Member
*****
Offline Offline

Activity: 3248
Merit: 773



View Profile
July 10, 2025, 08:51:28 AM
 #2

I can't believe there are already so many of these on the Play Store... it's really risky, so we need to be extra careful when downloading apps and always verify first.

As for keyloggers that can steal our passwords, it’s a serious risk, especially if we don’t use 2FA. But if we do have 2FA enabled, we're at least protected by that extra layer of security, since a confirmation is required through our phone number or authentication app before anyone can proceed. I think that's the best security measure available right now, and honestly, everyone should be using it.

.
 betpanda.io 
 
ANONYMOUS & INSTANT
.......ONLINE CASINO.......
▄███████████████████████▄
█████████████████████████
█████████████████████████
████████▀▀▀▀▀▀███████████
████▀▀▀█░▀▀░░░░░░▄███████
████░▄▄█▄▄▀█▄░░░█▄░▄█████
████▀██▀░▄█▀░░░█▀░░██████
██████░░▄▀░░░░▐░░░▐█▄████
██████▄▄█░▀▀░░░█▄▄▄██████
█████████████████████████
█████████████████████████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
██████████▀░░░▀██████████
█████████░░░░░░░█████████
███████░░░░░░░░░███████
████████░░░░░░░░░████████
█████████▄░░░░░▄█████████
███████▀▀▀█▄▄▄█▀▀▀███████
██████░░░░▄░▄░▄░░░░██████
██████░░░░█▀█▀█░░░░██████
██████░░░░░░░░░░░░░██████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
██████████▀▀▀▀▀▀█████████
███████▀▀░░░░░░░░░███████
██████░░░░░░░░░░░░▀█████
██████░░░░░░░░░░░░░░▀████
██████▄░░░░░░▄▄░░░░░░████
████▀▀▀▀▀░░░█░░█░░░░░████
████░▀░▀░░░░░▀▀░░░░░█████
████░▀░▀▄░░░░░░▄▄▄▄██████
█████░▀░█████████████████
█████████████████████████
▀███████████████████████▀
.
SLOT GAMES
....SPORTS....
LIVE CASINO
▄░░▄█▄░░▄
▀█▀░▄▀▄░▀█▀
▄▄▄▄▄▄▄▄▄▄▄   
█████████████
█░░░░░░░░░░░█
█████████████

▄▀▄██▀▄▄▄▄▄███▄▀▄
▄▀▄█████▄██▄▀▄
▄▀▄▐▐▌▐▐▌▄▀▄
▄▀▄█▀██▀█▄▀▄
▄▀▄█████▀▄████▄▀▄
▀▄▀▄▀█████▀▄▀▄▀
▀▀▀▄█▀█▄▀▄▀▀

Regional Sponsor of the
Argentina National Team
btcltcdigger
Hero Member
*****
Offline Offline

Activity: 2394
Merit: 855


Gone where no rabbit has gone before...


View Profile
July 10, 2025, 08:52:49 AM
 #3

PDF's by itself have macros inside, which are ran by just opening the document. Never ever open any pdf or excel when someone you don't know sends it to you.
If you do, it's probably infected and will fuck up your device, and steal your data. PDF's are bad, unless you know exactly what it is and who it's from

▄▄█████████████████▄▄
▄█████████████████████▄
███▀▀█████▀▀░░▀▀███████

██▄░░▀▀░░▄▄██▄░░█████
█████░░░████████░░█████
████▌░▄░░█████▀░░██████
███▌░▐█▌░░▀▀▀▀░░▄██████
███░░▌██░░▄░░▄█████████
███▌░▀▄▀░░█▄░░█████████
████▄░░░▄███▄░░▀▀█▀▀███
██████████████▄▄░░░▄███
▀█████████████████████▀
▀▀█████████████████▀▀
..Rainbet.com..
CRYPTO CASINO & SPORTSBOOK
|
█▄█▄█▄███████▄█▄█▄█
███████████████████
███████████████████
███████████████████
█████▀█▀▀▄▄▄▀██████
█████▀▄▀████░██████
█████░██░█▀▄███████
████▄▀▀▄▄▀███████
█████████▄▀▄██
█████████████████
███████████████████
██████████████████
███████████████████
 
 $20,000 
WEEKLY RAFFLE
|



█████████
█████████ ██
▄▄█░▄░▄█▄░▄░█▄▄
▀██░▐█████▌░██▀
▄█▄░▀▀▀▀▀░▄█▄
▀▀▀█▄▄░▄▄█▀▀▀
▀█▀░▀█▀
10K
WEEKLY
RACE
100K
MONTHLY
RACE
|

██









█████
███████
███████
█▄
██████
████▄▄
█████████████▄
███████████████▄
░▄████████████████▄
▄██████████████████▄
███████████████▀████
██████████▀██████████
██████████████████
░█████████████████▀
░░▀███████████████▀
████▀▀███
███████▀▀
████████████████████   ██
 
..►PLAY...
 
████████   ██████████████
EluguHcman
Sr. Member
****
Offline Offline

Activity: 854
Merit: 418



View Profile WWW
July 10, 2025, 09:34:23 AM
 #4

There is a new banking trojan known as Anatsa as it steals users information and other keylogging attacks. And why it should concern us crypto users? It's because some of us might have stored a lot of information as well together with our banking info and so it's a shooting two birds with one stone.

And so there is a chance that it might evolved into a full blown malware to target crypto wallets and everything related to it. So this is just a fair warning to everyone.
https://www.threatfabric.com/blogs/anatsa-targets-north-america-uses-proven-mobile-campaign-process
OP check the link, I really tried to click on it to read through in other to figure how effective or how the system of the trojan app works but seem invalid. That is by the way.

However, either way, whether it is about the banks of crypto, every news that has to do with threats to the lost of funds is worth sharing.
Even if this deceptive or malicious app program does not particularly targets crypto users, to be frank, it still have something to do with us because in as much as Bitcoin has not been widely used in both local and international in the acceptance for payments and services, there is no doubt, we all do stil uses the banks to fascinated out transactions. So, any crypto user can still be affected if on target and we are igbirants or not aware of the trick.

And as well, the funds we may been budgeting to buy our Bitcoins can be holding in the banks and if anything like looses happens to it thereby, then it has effectively disrupted our plans of buying anymore or in the main time.
So we ought just get to be careful as anything that has to do with money is at the utmost high value.

But I still hope to read through the news OP. Maybe try fix it up.












██
██
██████
R


▀▀██████▄▄
████████████████
▀█████▀▀▀█████
████████▌███▐████
▄█████▄▄▄█████
████████████████
▄▄██████▀▀
LLBIT
██████
██
██
██████
██
██
██
██
██
██
██
██
██
██
██
██████
██████████████
 
 TH#1 SOLANA CASINO 
██████████████
██████
██
██
██
██
██
██
██
██
██
██
██
██████
████████████▄
▀▀██████▀▀███
██▄▄▀▀▄▄████
████████████
██████████
███▀████████
▄▄█████████
████████████
████████████
████████████
████████████
█████████████
████████████▀
████████████▄
▀▀▀▀▀▀▀██████
████████████
███████████
██▄█████████
████▄███████
████████████
█░▀▀████████
▀▀██████████
█████▄█████
████▀▄▀████
▄▄▄▄▄▄▄██████
████████████▀
[
[
5,000+
GAMES
INSTANT
WITHDRAWALS
][
][
HUGE
   REWARDS   
VIP
PROGRAM
]
]
████
██
██
██
██
██
██
██
██
██
██
██
████
████████████████████████████████████████████████
 
PLAY NOW
 

████████████████████████████████████████████████
████
██
██
██
██
██
██
██
██
██
██
██
████
tech30338
Full Member
***
Offline Offline

Activity: 924
Merit: 226



View Profile WWW
July 10, 2025, 09:48:29 AM
 #5

Okay so the purpose is to lure people to download a free application, since people like free, they will check for mobile bank applications in you're mobile application, once found it will create a fake login, or it will run and open a fake login page for the app, then steal those information.
too bad the mobile phone antivirus did not detect it.
Just want to add the Spark kitty since they have been detected that the one detected that stealing wallet data, both iOS and android are being attack, getting seed phrase that are screenshot, so be careful taking pictures or screenshot of you're seed phrase.

Trêvoid
Copper Member
Sr. Member
****
Offline Offline

Activity: 294
Merit: 366


CRYPTO ⇄ CRYPTO █ No KYC / AML


View Profile
July 10, 2025, 11:50:54 AM
 #6

There is a new banking trojan known as Anatsa as it steals users information and other keylogging attacks. And why it should concern us crypto users? It's because some of us might have stored a lot of information as well together with our banking info and so it's a shooting two birds with one stone.

And so there is a chance that it might evolved into a full blown malware to target crypto wallets and everything related to it. So this is just a fair warning to everyone.

Sample download on Google Play:



And probably another look that we shouldn't blindly trust anything what we see on the Big G.

https://www.threatfabric.com/blogs/anatsa-targets-north-america-uses-proven-mobile-campaign-process




Thanks OP, best thing to do is be cautious with downloads, even from sources like Google Play.

sokani
Hero Member
*****
Offline Offline

Activity: 1022
Merit: 523



View Profile WWW
July 10, 2025, 11:59:15 AM
 #7

Thanks for sharing OP. It's worrisome that about 50k users have downloaded the malicious app. You can imagine the harm these scammers have inflicted on unsuspecting users. I checked on the Playstore and I couldn't find the app, but I won't be surprised if it pops up again with another name.

But I still hope to read through the news OP. Maybe try fix it up.
Try this one:
https://www.threatfabric.com/blogs/anatsa-targets-north-america-uses-proven-mobile-campaign-process

But If you can't, maybe your IP has been restricted from accessing these sites. Try using a VPN.

████████▄▄▄▄▄▄▀▀▀▀▀▀▄
███▄▀▀▀▀▀███████████
███▐▌████████████▀█▀▐▌
███▐▌███▄█▀█████████████████▄▄▄▄
▄▀█████▐█████████▄▄▄▐█▌▄█▌██▀▀
██████▐███▐██▌▄█▀▀▀▐█████▀███▄
▐█
██▐▌██▐████▌█▌█▌███▐█▌█▄▄▄▄██
▐██
▐▌██▐█▌▐█▀█▌▀█▄▄█▐███▀▀▀▀▀▀
████████▐█▌█▌▀▀▀██▀▀████▄▌████▄
███▄███▌▐████▄██▌█▌██▐████▌█▌▄█▀
██▐█▄▄▄▄██████████▌██▐████▌█▌▐██
███▀███▀▀████▌█████▄▄▐█▄▄█▌██▀▀
████████████▀███▌▀▀▀▀██▀▀

 ......NO FEES ON BITCOIN WITHDRAWALS...... 

▄▄███████▄▄
▄███████████████▄
▄███████████████████▄
▄█████████████████████▄
▄███████████████████████▄
█████████████████████████
████████████████████████
█████████████████████████
▀██████████████████████▀
▀█████████████████████▀
▀███████████████████▀
▀███████████████▀
▀▀███████▀▀

▀███████████▀
[
[
RELOAD
BONUS
 

RAKEBACK
BONUS
]
]
[
[
FREE
COINS
 

VIP
REWARDS
]
]
 
........► Play Now .... 
Cricktor
Legendary
*
Offline Offline

Activity: 1288
Merit: 3075



View Profile
July 13, 2025, 04:48:33 AM
Merited by btc_angela (1), sokani (1)
 #8

Thanks for sharing OP. It's worrisome that about 50k users have downloaded the malicious app.
The app wasn't malicious when it built and grew its user base.

The infection pathway is not so new. Publish an app of popular demand that's actually working well to gain a user base quickly. Later publish an update to the app that has some download dropper malicious code that passed app store detection. This dropper code then downloads the main malicious code which does the main nasty malware things (the article speaks about, it installs a separate malicious app on the target's Android mobile phone; I have questions to this).

I have a few points to highlight where possibly mobile phone users are a bit reckless and should question their opsec while using their phones for banking, crypto coin stuff and other important stuff.

You're reckless (less politely: stupid) if you install a file viewer app from a developer with name "Hybrid Cars Simulator, Drift & Racing" as shown by OP and taken from linked article. Well, this is an obviously suspicious name case. A less suspicious developer name compared to the app's purpose wouldn't ring alarm bells, sure.

The malicious actors who are well funded often buy existing developer accounts because those accounts likely have less trouble to publish new apps or updates to existing apps which in some cases are renamed to something that suits the malicious actor better for a new malware campaign. This is in most cases cheaper than to develop an own new developer account. But obviously they can't buy large successful dev accounts.

Don't install apps that look fancy or are just trending because they're free. Do you really need a new app on your device where you basically can't really trust the developer. Be caucious if a developer publishes new apps in completely different app genres compared to its past app publishing history. App reviews don't help too much because most of them could be fake and bought.


Normally an app can't install another app without special permission that needs to be granted. Normal Android will ask you if you really want to allow this and/or that you need to change some permissions to allow an app to install other apps (e.g. F-Droid app store need such special permissions).

An Android mobile phone user shouldn't grant permissions that (s)he doesn't understand why they're necessary. Especially when the permissions don't seem appropriate to an app's primary purpose. Yes, I know, this is not easy to answer and distinguish.

The malicious dropper code could of course exploit some bugs in Android. But such bugs are precious, especially when they're so-called zero-days (yet unknown/non-published new exploits). Malware that uses zero-days, publishes those new attack vectors to the malware research community when they're caught in-the-wild.


As temporary final remark: do you really think it's wise to use your daily driver mobile phone, with all the app shit users commonly install on such daily use devices, for mobile banking, mobile crypto wallets, anything else of considerable value?

If you really need and want to do mobile banking and mobile crypto wallet or trading stuff, I would highly recommend to use a separate mobile device where you de-install anything that's not required for mobile banking and crypto wallets. Don't use this separate mobile for daily stuff, only for those narrowed special use cases.

Personally, I don't do banking stuff on my mobile phone, I do this from my Linux desktop. My mobile phone wallets only have pocket money amounts, rarely more than, say equiv. to 100-300 dollars worth of value.

NotATether
Legendary
*
Offline Offline

Activity: 2128
Merit: 9052


Trêvoid █ No KYC-AML Crypto Swaps


View Profile WWW
July 13, 2025, 07:53:02 AM
 #9

I can't believe there are already so many of these on the Play Store... it's really risky, so we need to be extra careful when downloading apps and always verify first.

It's really dangerous for people who simply install an app and allow them to auto-update. Imagine if the developer account is sold and a malicious update is pushed. That would be chaotic for millions of users.

As for keyloggers that can steal our passwords, it’s a serious risk, especially if we don’t use 2FA. But if we do have 2FA enabled, we're at least protected by that extra layer of security, since a confirmation is required through our phone number or authentication app before anyone can proceed. I think that's the best security measure available right now, and honestly, everyone should be using it.

Would anyone who is using biometrics even notice? As far as apps installed on my phone go, the ones that state that they need my fingerprint for a defined purpose could ask for it again if I navigate to the app, and I wouldn't find it suspicious - and have no way of knowing.

.
 betpanda.io 
 
ANONYMOUS & INSTANT
.......ONLINE CASINO.......
▄███████████████████████▄
█████████████████████████
█████████████████████████
████████▀▀▀▀▀▀███████████
████▀▀▀█░▀▀░░░░░░▄███████
████░▄▄█▄▄▀█▄░░░█▄░▄█████
████▀██▀░▄█▀░░░█▀░░██████
██████░░▄▀░░░░▐░░░▐█▄████
██████▄▄█░▀▀░░░█▄▄▄██████
█████████████████████████
█████████████████████████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
██████████▀░░░▀██████████
█████████░░░░░░░█████████
███████░░░░░░░░░███████
████████░░░░░░░░░████████
█████████▄░░░░░▄█████████
███████▀▀▀█▄▄▄█▀▀▀███████
██████░░░░▄░▄░▄░░░░██████
██████░░░░█▀█▀█░░░░██████
██████░░░░░░░░░░░░░██████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
██████████▀▀▀▀▀▀█████████
███████▀▀░░░░░░░░░███████
██████░░░░░░░░░░░░▀█████
██████░░░░░░░░░░░░░░▀████
██████▄░░░░░░▄▄░░░░░░████
████▀▀▀▀▀░░░█░░█░░░░░████
████░▀░▀░░░░░▀▀░░░░░█████
████░▀░▀▄░░░░░░▄▄▄▄██████
█████░▀░█████████████████
█████████████████████████
▀███████████████████████▀
.
SLOT GAMES
....SPORTS....
LIVE CASINO
▄░░▄█▄░░▄
▀█▀░▄▀▄░▀█▀
▄▄▄▄▄▄▄▄▄▄▄   
█████████████
█░░░░░░░░░░░█
█████████████

▄▀▄██▀▄▄▄▄▄███▄▀▄
▄▀▄█████▄██▄▀▄
▄▀▄▐▐▌▐▐▌▄▀▄
▄▀▄█▀██▀█▄▀▄
▄▀▄█████▀▄████▄▀▄
▀▄▀▄▀█████▀▄▀▄▀
▀▀▀▄█▀█▄▀▄▀▀

Regional Sponsor of the
Argentina National Team
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!