{"id":781314,"date":"2026-07-05T21:30:09","date_gmt":"2026-07-05T21:30:09","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/781314\/"},"modified":"2026-07-05T21:30:09","modified_gmt":"2026-07-05T21:30:09","slug":"android-users-warned-about-fake-app-stealing-bank-details","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/781314\/","title":{"rendered":"Android users warned about fake app stealing bank details"},"content":{"rendered":"<p>\n  The malicious app is disguised as a document reader and has been downloaded more than 100,000 times.\n<\/p>\n<p>\n  Once downloaded, it secretly delivers the Anatsa banking trojan onto the Android device.\n<\/p>\n<p>\n  Zimperium explains: &#8220;Victims are lured into downloading seemingly harmless apps that promise to open or manage documents.\n<\/p>\n<p>\n  &#8220;Instead, it installs malicious code capable of stealing sensitive data, harvesting credentials, and maintaining persistent access to the device.&#8221;\n<\/p>\n<p>\n    Fraud is now 45% of all crime in England and Wales.<\/p>\n<p>We broke down exactly what this means for enterprise fraud, security and compliance leaders \u2014 and what the new regulatory obligations mean for your organization. <a href=\"https:\/\/t.co\/xcIHroPEdY\" target=\"_blank\" rel=\"nofollow\">https:\/\/t.co\/xcIHroPEdY<\/a> <a href=\"https:\/\/t.co\/wdGXI7VbPV\" target=\"_blank\" rel=\"nofollow\">pic.twitter.com\/wdGXI7VbPV<\/a>\n  <\/p>\n<p>\n    \u2014 Zimperium (@Zimperium) <a href=\"https:\/\/x.com\/Zimperium\/status\/2067302533572280736?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"nofollow\">June 17, 2026<\/a>\n  <\/p>\n<p>\n  The fake app has bypassed Google&#8217;s automated security checks and was recently found to be live on the Play Store despite being flagged by security researchers.\n<\/p>\n<p>  How the\u00a0Anatsa banking trojan works<\/p>\n<p>\n  The Anatsa Trojan is designed to steal sensitive financial data and drain users\u2019 bank accounts by hijacking their mobile devices.\n<\/p>\n<p>\n  The application uses a multi-stage infection strategy to avoid initial detection, according to <a href=\"https:\/\/cyberpress.org\/fake-document-reader-malware\/?ref=ed_direct\" target=\"_blank\" rel=\"nofollow noopener\">Cyber Press<\/a>.\n<\/p>\n<p>\n  The news platform said: &#8220;When a user downloads the fake document reader, the application functions normally at first, displaying the expected user interface to avoid suspicion.\n<\/p>\n<p>\n  &#8220;However, in the background, the application quietly connects to a remote server to download the secondary malicious payload.\n<\/p>\n<p>\n  &#8220;Once the Anatsa payload is installed on the victim\u2019s device, it immediately requests sweeping permissions, particularly targeting Android\u2019s Accessibility Services.&#8221;\n<\/p>\n<p>\n  By gaining access to these privileges, the malware can:\n<\/p>\n<p>  Observe the user\u2019s screen<\/p>\n<p>  Capture keystrokes<\/p>\n<p>  Interact with the device\u2019s interface<\/p>\n<p>\n  The primary objective of the Anatsa Trojan is to monitor banking and financial apps.\n<\/p>\n<p>\n  Cyber Press continues: &#8220;When a victim attempts to log in to a targeted banking app, Anatsa intercepts the process and displays a fake overlay that perfectly mimics the legitimate login page.\n<\/p>\n<p>\n  &#8220;Unsuspecting users enter their credentials into this fraudulent form, directly handing their usernames, passwords, and two-factor authentication codes to the attackers.&#8221;\n<\/p>\n<p>\n  The malware can also gain access to SMS messages and\u00a0approve transaction prompts.\n<\/p>\n<p>  Check for suspicious apps to avoid the Anatsa Trojan<\/p>\n<p>\n  Android users who have downloaded any suspicious\u00a0document readers recently should &#8220;immediately review their installed applications and monitor their bank statements for unauthorized activity&#8221;.\n<\/p>\n<p>\n  Have you downloaded any suspicious apps recently? Let us know in the comments below.\n<\/p>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"The malicious app is disguised as a document reader and has been downloaded more than 100,000 times. Once&hellip;\n","protected":false},"author":2,"featured_media":781315,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[16],"tags":[64,63,203,105],"class_list":["post-781314","post","type-post","status-publish","format-standard","has-post-thumbnail","category-mobile","tag-au","tag-australia","tag-mobile","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/781314","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=781314"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/781314\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/781315"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=781314"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=781314"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=781314"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}