Skip to content
logo The magazine for digital lifestyle and entertainment
Android Google News Play Store Security All topics
New Investigation

Warning: Nearly 150,000 Android Smartphones Infected with Banking Trojan

Malware Attacks on Android Smartphones Are Increasing
Malware Attacks on Android Smartphones Are Increasing Photo: Getty Images
Share article
Adrian Mühlroth

May 29, 2024, 4:05 pm | Read time: 2 minutes

According to a new study, more than five million Android smartphones have been infected with malware in recent months. This includes a highly dangerous banking Trojan. TECHBOOK reveals which affected apps you should delete immediately.

Despite all security measures, the Google Play Store remains a hotspot for malware-infected apps. Malicious actors are finding increasingly sophisticated ways to sneak their malware onto Android smartphones undetected. Attack campaigns with the banking Trojan “Anatsa” are particularly on the rise.

Malware Disguises Itself as Legitimate App

Back in February, the security company ThreatFabric published a report stating that “Anatsa” had been installed on more than 150,000 devices. Now, cybersecurity researchers from Zscaler have released a study showing that hackers have infected 5.5 million Android devices with malware through current campaigns. The data indicates that “Anatsa” continues to spread.

The banking Trojan is introduced to smartphones via so-called “dropper” apps. These apps appear legitimate and are usually free. They are often in-demand tools such as PDF readers, file managers, and QR code scanners. This gives the infected apps more visibility and leads to more installations. However, after installation, the apps communicate with a server that sends the actual malware as a “payload.” Once the banking Trojan is installed, it can take over the smartphone and execute financial transactions on behalf of the users. It is considered one of the most dangerous banking Trojans in circulation.

Users Should Delete These Apps Immediately

The experts at Zscaler have identified two apps that infect smartphones with “Anatsa,” each with more than 70,000 installations. The company informed Google of the findings in advance, and the apps have since been removed, and the associated developer accounts have been suspended.

However, if you have already installed the apps listed below, you should delete them immediately.

  • PDF Reader & File Manager (developed by TSARKA Watchfaces)
  • QR Reader & File Manager (developed by risovanui)

This article is a machine translation of the original German version of TECHBOOK and has been reviewed for accuracy and quality by a native speaker. For feedback, please contact us at info@techbook.de.

You have successfully withdrawn your consent to the processing of personal data through tracking and advertising when using this website. You can now consent to data processing again or object to legitimate interests.