{"id":408875,"date":"2026-05-02T20:52:36","date_gmt":"2026-05-02T20:52:36","guid":{"rendered":"https:\/\/www.newsbeep.com\/nz\/408875\/"},"modified":"2026-05-02T20:52:36","modified_gmt":"2026-05-02T20:52:36","slug":"fake-document-reader-on-google-play-with-10k-downloads-installing-anatsa-malware","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/nz\/408875\/","title":{"rendered":"Fake Document Reader On Google Play With 10K Downloads Installing Anatsa Malware"},"content":{"rendered":"<p>A new fake document reader app found on the Google Play Store has been silently installing Anatsa, a powerful Android banking trojan, on thousands of user devices. <\/p>\n<p>The malicious application surpassed 10,000 downloads before Google removed it, putting a significant number of Android users at direct risk of financial fraud and credential theft.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/7f85a9ec-27ba-4232-a84b-f91352c45016\/Fake-Document-Reader-On-Google-Play-With-10K-Downloads-Installing-Anatsa-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYE4XRTNPXR&amp;Signature=n4Sv8FRkdZ%2BefHB9YorChccd3ho%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEA4aCXVzLWVhc3QtMSJGMEQCIBH7RhuLIjp7mSctMA9Zf70ZfuxGQmJdFxBFk3X14Yh0AiAXgbyreX%2BNV45UXYEAdFd6IoYrCKWNbwkB37hNCqiVIir8BAjX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIM1bQOPjc2ZS1NxnkDKtAEuNXUdTehujQM1zdgxvd%2F8LfEhPQra8fP6TqUYCT%2FufD%2B8uNGPv4hQtGCmywQ3Efe6U9jvK4CHqZhSSErSrHvSRfXtZbjj5F3pz5gS5aLZQThkAd0ByTmdXyzW74xlPDNPudVXSYEdSKVKpAYsfYx5xqBNfxoS3ho%2FWAyxSaE5zoOb4gg4VAJJiXGTksBpuBe7III8RSP540LztgKBpnzkBvXsIuKjEGqTc6I5xUxhVkK7LkI1IUdumZtldOF0rs2y31bD7tKzjkPMUXc51jx8tYmYU08oLhQVpDZehBXqgdBZQ47kN2c2c4JTkyQUCp%2F1UA4OQbhzsinEYHU4t8DPCkv%2F5veCeMealKvAXlts0jEpgWiNz7Xofh%2FtszaNU%2BWw1RQbKVJ5ZYM%2FI3MEJ5d5tmcrwFKT8P9uaWiXz8SQv9o5Q%2FxvcGXElgPK6%2BtHqwYBxivZSu2ik6oC1GaLtjQWIKuFcmAxrxZEWdW6wIj%2FQ8rHqn%2F8skd3bE3CU8E2hOWDAlxvX0CF066BBzUxEK5%2BEfoDGXJALZsP0s%2BQwt4nA7cOuKViakh%2FEYEp9J7I0nrOknLXsd79dMSaDool5rNKtRcsvZK4Z3H3T2rVme1CyEWvg1WWu4fPZ6NS5N2XP8fJCJTXQGSlKlEud9zeCaDvxlAXU7LlDor5XSjBrgOhDHVz4CBC2K4BImwLaOKLv1abkA5UOmAqKsyTMEWbNzV0BvvPXGLKpZg0R8RKfjb3FtbbQDoRlUJlGimFtv2dSSIsIQ%2B%2BxgdJfB4I1f8UDBaOjD%2Bj8HPBjqZAap5DCQL29x4QNxN2rlVghitVHUJx3hUlNT77ck2LsZkqsSjg5WYAMWx7YzjmZLBj%2B8IK%2FJCWZ7ylBn1lO9SFfxC%2ByvzDqoIiBVlGtNH5I0Lm7IM53gUGoRmPGndHF1rdVVa1gYCFyMcxfSP5P%2BsVJy%2BlLeXyCKyUFvZEtIINQW3%2Fkg5ZPUrGQcal1rLKKAaBEymCMoUgvJ0dQ%3D%3D&amp;Expires=1777355492\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><\/p>\n<p>Anatsa is not a new name in mobile security. The malware first surfaced in 2020 as an Android banking trojan built to steal credentials, record keystrokes, and perform fraudulent transactions on infected devices without user knowledge. <\/p>\n<p>Over the years, it has grown into one of the most persistent mobile banking threats, with its latest variant now targeting more than 831 financial institutions globally, including newly added banks and cryptocurrency platforms in countries like Germany and South Korea.<\/p>\n<p>Researchers at <a href=\"https:\/\/x.com\/Threatlabz\/status\/2048806728083571115?s=20\" id=\"https:\/\/x.com\/Threatlabz\/status\/2048806728083571115?s=20\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Zscaler ThreatLabz identified the malicious application<\/a> on the Google Play Store and published their findings on April 27, 2026. The app was disguised as a file reader under the package name\u00a0com.groundstation.informationcontrol.filestation_browsefiles_readdocs\u00a0and had surpassed 10,000 downloads before Google removed it from the platform. <\/p>\n<p>This incident is yet another chapter in Anatsa\u2019s ongoing campaign, which has repeatedly used benign-looking utility apps to bypass app store defenses and reach real users at scale.<a href=\"https:\/\/www.zscaler.com\/blogs\/security-research\/technical-analysis-anatsa-campaigns-android-banking-malware-active-google\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/7f85a9ec-27ba-4232-a84b-f91352c45016\/Fake-Document-Reader-On-Google-Play-With-10K-Downloads-Installing-Anatsa-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYE4XRTNPXR&amp;Signature=n4Sv8FRkdZ%2BefHB9YorChccd3ho%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEA4aCXVzLWVhc3QtMSJGMEQCIBH7RhuLIjp7mSctMA9Zf70ZfuxGQmJdFxBFk3X14Yh0AiAXgbyreX%2BNV45UXYEAdFd6IoYrCKWNbwkB37hNCqiVIir8BAjX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIM1bQOPjc2ZS1NxnkDKtAEuNXUdTehujQM1zdgxvd%2F8LfEhPQra8fP6TqUYCT%2FufD%2B8uNGPv4hQtGCmywQ3Efe6U9jvK4CHqZhSSErSrHvSRfXtZbjj5F3pz5gS5aLZQThkAd0ByTmdXyzW74xlPDNPudVXSYEdSKVKpAYsfYx5xqBNfxoS3ho%2FWAyxSaE5zoOb4gg4VAJJiXGTksBpuBe7III8RSP540LztgKBpnzkBvXsIuKjEGqTc6I5xUxhVkK7LkI1IUdumZtldOF0rs2y31bD7tKzjkPMUXc51jx8tYmYU08oLhQVpDZehBXqgdBZQ47kN2c2c4JTkyQUCp%2F1UA4OQbhzsinEYHU4t8DPCkv%2F5veCeMealKvAXlts0jEpgWiNz7Xofh%2FtszaNU%2BWw1RQbKVJ5ZYM%2FI3MEJ5d5tmcrwFKT8P9uaWiXz8SQv9o5Q%2FxvcGXElgPK6%2BtHqwYBxivZSu2ik6oC1GaLtjQWIKuFcmAxrxZEWdW6wIj%2FQ8rHqn%2F8skd3bE3CU8E2hOWDAlxvX0CF066BBzUxEK5%2BEfoDGXJALZsP0s%2BQwt4nA7cOuKViakh%2FEYEp9J7I0nrOknLXsd79dMSaDool5rNKtRcsvZK4Z3H3T2rVme1CyEWvg1WWu4fPZ6NS5N2XP8fJCJTXQGSlKlEud9zeCaDvxlAXU7LlDor5XSjBrgOhDHVz4CBC2K4BImwLaOKLv1abkA5UOmAqKsyTMEWbNzV0BvvPXGLKpZg0R8RKfjb3FtbbQDoRlUJlGimFtv2dSSIsIQ%2B%2BxgdJfB4I1f8UDBaOjD%2Bj8HPBjqZAap5DCQL29x4QNxN2rlVghitVHUJx3hUlNT77ck2LsZkqsSjg5WYAMWx7YzjmZLBj%2B8IK%2FJCWZ7ylBn1lO9SFfxC%2ByvzDqoIiBVlGtNH5I0Lm7IM53gUGoRmPGndHF1rdVVa1gYCFyMcxfSP5P%2BsVJy%2BlLeXyCKyUFvZEtIINQW3%2Fkg5ZPUrGQcal1rLKKAaBEymCMoUgvJ0dQ%3D%3D&amp;Expires=1777355492\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><\/p>\n<p lang=\"en\" dir=\"ltr\">ThreatLabz discovered another fake document reader in the Google Play Store with more than 10K downloads, which delivered the Anatsa Android trojan.<\/p>\n<p>Anatsa installer SHA256 hash: 5c9b09819b196970a867b1d459f9053da38a6a2721f21264324e0a8ffef01e20<br \/>Payload URL:\u2026 <a href=\"https:\/\/t.co\/CBAgWfaa4n\" rel=\"nofollow\">pic.twitter.com\/CBAgWfaa4n<\/a><\/p>\n<p>\u2014 Zscaler ThreatLabz (@Threatlabz) <a href=\"https:\/\/twitter.com\/Threatlabz\/status\/2048806728083571115?ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">April 27, 2026<\/a><\/p>\n<p>The app used a dropper technique to stay undetected during the store\u2019s review process. Once installed, it appeared to work normally as a document reader, showing no signs of <a href=\"https:\/\/cybersecuritynews.com\/qilin-ransomware-kill-edr\/\" id=\"146494\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">malicious activity<\/a>. <\/p>\n<p>In the background, it connected to a remote server and pulled down the Anatsa payload from\u00a0http:\/\/23.251.108[.]10:8080\/privacy.txt, silently installing the trojan without any user-visible alerts. This two-stage delivery is designed to beat app store reviews that only assess apps at the point of submission.<a href=\"https:\/\/thehackernews.com\/2025\/07\/anatsa-android-banking-trojan-hits.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/7f85a9ec-27ba-4232-a84b-f91352c45016\/Fake-Document-Reader-On-Google-Play-With-10K-Downloads-Installing-Anatsa-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYE4XRTNPXR&amp;Signature=n4Sv8FRkdZ%2BefHB9YorChccd3ho%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEA4aCXVzLWVhc3QtMSJGMEQCIBH7RhuLIjp7mSctMA9Zf70ZfuxGQmJdFxBFk3X14Yh0AiAXgbyreX%2BNV45UXYEAdFd6IoYrCKWNbwkB37hNCqiVIir8BAjX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIM1bQOPjc2ZS1NxnkDKtAEuNXUdTehujQM1zdgxvd%2F8LfEhPQra8fP6TqUYCT%2FufD%2B8uNGPv4hQtGCmywQ3Efe6U9jvK4CHqZhSSErSrHvSRfXtZbjj5F3pz5gS5aLZQThkAd0ByTmdXyzW74xlPDNPudVXSYEdSKVKpAYsfYx5xqBNfxoS3ho%2FWAyxSaE5zoOb4gg4VAJJiXGTksBpuBe7III8RSP540LztgKBpnzkBvXsIuKjEGqTc6I5xUxhVkK7LkI1IUdumZtldOF0rs2y31bD7tKzjkPMUXc51jx8tYmYU08oLhQVpDZehBXqgdBZQ47kN2c2c4JTkyQUCp%2F1UA4OQbhzsinEYHU4t8DPCkv%2F5veCeMealKvAXlts0jEpgWiNz7Xofh%2FtszaNU%2BWw1RQbKVJ5ZYM%2FI3MEJ5d5tmcrwFKT8P9uaWiXz8SQv9o5Q%2FxvcGXElgPK6%2BtHqwYBxivZSu2ik6oC1GaLtjQWIKuFcmAxrxZEWdW6wIj%2FQ8rHqn%2F8skd3bE3CU8E2hOWDAlxvX0CF066BBzUxEK5%2BEfoDGXJALZsP0s%2BQwt4nA7cOuKViakh%2FEYEp9J7I0nrOknLXsd79dMSaDool5rNKtRcsvZK4Z3H3T2rVme1CyEWvg1WWu4fPZ6NS5N2XP8fJCJTXQGSlKlEud9zeCaDvxlAXU7LlDor5XSjBrgOhDHVz4CBC2K4BImwLaOKLv1abkA5UOmAqKsyTMEWbNzV0BvvPXGLKpZg0R8RKfjb3FtbbQDoRlUJlGimFtv2dSSIsIQ%2B%2BxgdJfB4I1f8UDBaOjD%2Bj8HPBjqZAap5DCQL29x4QNxN2rlVghitVHUJx3hUlNT77ck2LsZkqsSjg5WYAMWx7YzjmZLBj%2B8IK%2FJCWZ7ylBn1lO9SFfxC%2ByvzDqoIiBVlGtNH5I0Lm7IM53gUGoRmPGndHF1rdVVa1gYCFyMcxfSP5P%2BsVJy%2BlLeXyCKyUFvZEtIINQW3%2Fkg5ZPUrGQcal1rLKKAaBEymCMoUgvJ0dQ%3D%3D&amp;Expires=1777355492\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><a href=\"https:\/\/www.zscaler.com\/blogs\/security-research\/android-document-readers-and-deception-tracking-latest-updates-anatsa\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><\/p>\n<p>This method of staying clean at first and then downloading malware later has been a signature of Anatsa\u2019s campaigns for years. <\/p>\n<p>Since Google Play\u2019s security scans focus on the initial version of an app, the trojan can enter the platform undetected and wait until it has enough installations before activating. By that point, the malware is already running on thousands of real devices.<\/p>\n<p>Infection Mechanism and Detection Evasion<\/p>\n<p>Once Anatsa\u2019s payload is running on a device, it requests accessibility permissions from the user. If granted, the malware automatically activates a broader set of privileges, including overlaying content on top of other apps, intercepting SMS messages, and displaying full-screen alerts. <\/p>\n<p>These capabilities are used to capture user activity, steal banking credentials, and interfere with legitimate app interactions without raising obvious alarms.<\/p>\n<p>To stay hidden from security tools, Anatsa hides its DEX file inside a corrupted ZIP archive with invalid compression flags. The file only executes at runtime and is deleted immediately after loading, making it very difficult for static tools to catch. <\/p>\n<p>The payload is further embedded inside a JSON file that is dropped and erased during execution, leaving minimal evidence of the infection on the device.<\/p>\n<p>Anatsa encrypts all traffic to its command-and-control servers using a single-byte XOR key. In this campaign, the C2 servers were hosted at\u00a0http:\/\/172.86.91[.]94\/api\/,\u00a0http:\/\/193.24.123[.]18:85\/api\/, and\u00a0http:\/\/162.252.173[.]37:85\/api\/. <\/p>\n<p>These servers deliver <a href=\"https:\/\/cybersecuritynews.com\/fake-lpg-payment-and-kyc-update\/\" id=\"146864\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">fake banking<\/a> login overlays that appear directly over legitimate banking apps, tricking users into entering their credentials on fraudulent pages that look completely real.<a href=\"https:\/\/www.cryptika.com\/anatsa-malware-attacking-android-devices-to-steal-login-credentials-and-monitor-keystrokes\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/7f85a9ec-27ba-4232-a84b-f91352c45016\/Fake-Document-Reader-On-Google-Play-With-10K-Downloads-Installing-Anatsa-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYE4XRTNPXR&amp;Signature=n4Sv8FRkdZ%2BefHB9YorChccd3ho%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEA4aCXVzLWVhc3QtMSJGMEQCIBH7RhuLIjp7mSctMA9Zf70ZfuxGQmJdFxBFk3X14Yh0AiAXgbyreX%2BNV45UXYEAdFd6IoYrCKWNbwkB37hNCqiVIir8BAjX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIM1bQOPjc2ZS1NxnkDKtAEuNXUdTehujQM1zdgxvd%2F8LfEhPQra8fP6TqUYCT%2FufD%2B8uNGPv4hQtGCmywQ3Efe6U9jvK4CHqZhSSErSrHvSRfXtZbjj5F3pz5gS5aLZQThkAd0ByTmdXyzW74xlPDNPudVXSYEdSKVKpAYsfYx5xqBNfxoS3ho%2FWAyxSaE5zoOb4gg4VAJJiXGTksBpuBe7III8RSP540LztgKBpnzkBvXsIuKjEGqTc6I5xUxhVkK7LkI1IUdumZtldOF0rs2y31bD7tKzjkPMUXc51jx8tYmYU08oLhQVpDZehBXqgdBZQ47kN2c2c4JTkyQUCp%2F1UA4OQbhzsinEYHU4t8DPCkv%2F5veCeMealKvAXlts0jEpgWiNz7Xofh%2FtszaNU%2BWw1RQbKVJ5ZYM%2FI3MEJ5d5tmcrwFKT8P9uaWiXz8SQv9o5Q%2FxvcGXElgPK6%2BtHqwYBxivZSu2ik6oC1GaLtjQWIKuFcmAxrxZEWdW6wIj%2FQ8rHqn%2F8skd3bE3CU8E2hOWDAlxvX0CF066BBzUxEK5%2BEfoDGXJALZsP0s%2BQwt4nA7cOuKViakh%2FEYEp9J7I0nrOknLXsd79dMSaDool5rNKtRcsvZK4Z3H3T2rVme1CyEWvg1WWu4fPZ6NS5N2XP8fJCJTXQGSlKlEud9zeCaDvxlAXU7LlDor5XSjBrgOhDHVz4CBC2K4BImwLaOKLv1abkA5UOmAqKsyTMEWbNzV0BvvPXGLKpZg0R8RKfjb3FtbbQDoRlUJlGimFtv2dSSIsIQ%2B%2BxgdJfB4I1f8UDBaOjD%2Bj8HPBjqZAap5DCQL29x4QNxN2rlVghitVHUJx3hUlNT77ck2LsZkqsSjg5WYAMWx7YzjmZLBj%2B8IK%2FJCWZ7ylBn1lO9SFfxC%2ByvzDqoIiBVlGtNH5I0Lm7IM53gUGoRmPGndHF1rdVVa1gYCFyMcxfSP5P%2BsVJy%2BlLeXyCKyUFvZEtIINQW3%2Fkg5ZPUrGQcal1rLKKAaBEymCMoUgvJ0dQ%3D%3D&amp;Expires=1777355492\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><\/p>\n<p>The malware also performs emulation checks and verifies the device model before deploying the payload. If it detects a sandboxed or testing environment, it simply displays a clean file manager interface instead of launching the trojan. <\/p>\n<p>This built-in self-defense mechanism <a href=\"https:\/\/cybersecuritynews.com\/anatsa-malware-attacking-android-devices\/\" id=\"122740\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">helps Anatsa<\/a> remain undetected during automated analysis, giving it more time to operate freely on real user devices without being flagged.<\/p>\n<p>Android users should review the permissions any new app requests before approving them. Document readers and file managers have no legitimate reason to request accessibility permissions or SMS access. <\/p>\n<p>Keeping Google Play Protect turned on, avoiding apps from unfamiliar developers, and questioning any app that asks for unusual permissions are all practical steps worth taking. <\/p>\n<p>Anyone who installed the affected application should uninstall it immediately and scan their device with a trusted mobile <a href=\"https:\/\/cybersecuritynews.com\/best-cloud-security-tools\/\" id=\"11635\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">security tool<\/a>.<\/p>\n<p>Indicators of Compromise (IOCs):-<\/p>\n<p>IndicatorTypeDetail5c9b09819b196970a867b1d459f9053da38a6a2721f21264324e0a8ffef01e20Installer SHA256Anatsa dropper hash88fd72ac0cdab37c74ce14901c5daf214bd54f64e0e68093526a0076df4e042fPayload SHA256Anatsa core payload hashhttp:\/\/23.251.108[.]10:8080\/privacy.txtPayload URLRemote payload delivery serverhttp:\/\/172.86.91[.]94\/api\/C2 ServerAnatsa command-and-controlhttp:\/\/193.24.123[.]18:85\/api\/C2 ServerAnatsa command-and-controlhttp:\/\/162.252.173[.]37:85\/api\/C2 ServerAnatsa command-and-controlcom.groundstation.informationcontrol.filestation_browsefiles_readdocsPackage NameMalicious dropper app (removed)<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\">Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates,\u00a0Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/p>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"A new fake document reader app found on the Google Play Store has been silently installing Anatsa, a&hellip;\n","protected":false},"author":2,"featured_media":408876,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[16],"tags":[342,111,139,69,145],"class_list":["post-408875","post","type-post","status-publish","format-standard","has-post-thumbnail","category-mobile","tag-mobile","tag-new-zealand","tag-newzealand","tag-nz","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts\/408875","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/comments?post=408875"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/posts\/408875\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/media\/408876"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/media?parent=408875"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/categories?post=408875"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/nz\/wp-json\/wp\/v2\/tags?post=408875"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}