{"id":2563,"date":"2024-02-20T22:48:25","date_gmt":"2024-02-20T22:48:25","guid":{"rendered":"https:\/\/www.darkreading.com\/mobile-security\/new-wave-of-anatsa-banking-trojan-attacks-targets-android-users-in-europe"},"modified":"2024-02-20T22:48:25","modified_gmt":"2024-02-20T22:48:25","slug":"new-wave-of-anatsa-banking-trojans-targets-android-users-in-europe","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/02\/20\/new-wave-of-anatsa-banking-trojans-targets-android-users-in-europe\/","title":{"rendered":"New Wave of &#8216;Anatsa&#8217; Banking Trojans Targets Android Users in Europe"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt82c69306b391f4be\/65d5220805c1da040a7f8f2c\/android_Profit_Image_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/new-wave-of-anatsa-banking-trojans-targets-android-users-in-europe.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/new-wave-of-anatsa-banking-trojans-targets-android-users-in-europe.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A threat actor is using malware droppers disguised as legitimate mobile apps on Google&#8217;s Play store to distribute a dangerous banking Trojan dubbed &#8220;Anatsa&#8221; to Android users in several European countries.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The campaign has been ongoing for at least four months and is the latest salvo from the operators of the malware, which first surfaced in 2020 and has previously notched victims in the US, Italy, United Kingdom, France, Germany, and other countries.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Prolific Rate of Infections\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Prolific Rate of Infections<\/span><\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Researchers from ThreatFabric have been monitoring Anatsa since its initial discovery and spotted the new wave of attacks beginning in November 2023. <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.threatfabric.com\/blogs\/anatsa-trojan-returns-targeting-europe-and-expanding-its-reach#introduction\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">In a report this week,<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> the fraud detection vendor described the attacks as unfolding in multiple distinct waves targeting customers of banks in Slovakia, Slovenia, and the Czech Republic.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So far, Android users in the targeted regions have downloaded droppers for the malware from Google&#8217;s Play store at least 100,000 times since November. In a previous campaign during the first half of 2023 that ThreatFabric tracked, the threat actors accumulated over 130,000 installations of its weaponized droppers for Anatsa from Google&#8217;s mobile app store.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">ThreatFabric attributed the relatively high infection rates to the muti-stage approach the droppers on Google Play use to deliver Anatsa on Android devices. When the droppers initially get uploaded to Play, there&#8217;s nothing about them to suggest malicious behavior. It&#8217;s only after they land on Play that the droppers dynamically retrieve code for executing malicious actions from a remote command and control (C2) server.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">One of the droppers, disguised as a cleaner app, claimed to require permissions to Android&#8217;s Accessibility Service feature for what appeared to be a legitimate reason. Android&#8217;s Accessibility Service is a special type of feature designed to make it easier for users with disabilities and special needs to interact with Android apps. Threat actors have frequently exploited the feature to automate payload installation on Android devices and eliminate the need for any user interaction during the process.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Multi-Stage Approach\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Multi-Stage Approach<\/span><\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Initially the [cleaner] app appeared harmless, with no malicious code and its AccessibilityService not engaging in any harmful activities,&#8221; ThreatFabric said. &#8220;However, a week after its release, an update introduced malicious code. This update altered the AccessibilityService functionality, enabling it to execute malicious actions such as automatically clicking buttons once it received a configuration from the C2 server,&#8221; the vendor noted.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The files that the dropper dynamically retrieved from the C2 server included configuration info for a malicious DEX file for distributing Android application code; a DEX file itself with malicious code for payload installation, configuration with a payload URL, and finally code for downloading and installing Anatsa on the device.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The multi-stage, dynamically loaded approach used by the threat actors allowed each of the droppers that they used in the latest campaign to circumvent the tougher AccessibilityService restrictions Google implemented in Android 13, Threat Fabric said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For the latest campaign, the operator of Anatsa chose to use a total of five droppers disguised as free device-cleaner apps, PDF viewers, and PDF reader apps on Google Play. &#8220;These applications often reach the Top-3 in the &#8216;Top New Free&#8217; category, enhancing their credibility and lowering the guard of potential victims while increasing the chances of successful infiltration,&#8221; ThreatFabric said in its report. Once installed on a system, Anasta can steal credentials and other information that allow the threat actor to take over the device and later log into the user&#8217;s bank account and steal funds from it.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Like Apple, Google has implemented numerous security mechanisms in recent years to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/endpoint-security\/mobile-cyberattacks-soar-andoird-users\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">make it harder for threat actors to sneak malicious apps<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> into Android devices via its official mobile app store. One of the most significant among them is <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/security.googleblog.com\/2023\/10\/enhanced-google-play-protect-real-time.html\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">Google Play Protect<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, a built-in Android feature that scans app installations in real-time for signs of potentially malicious or harmful behavior, then alerts or disables the app if it finds anything suspicious. Android&#8217;s restricted settings feature has also made it much harder for threat actors to try and infect Android devices via sideloaded apps \u2014 or apps from unofficial application stores.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Even so, threat actors have managed to continue to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/application-security\/421-spyware-apps-downloaded-google-play\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">sneak malware onto Android devices<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> via Play by abusing features like Android&#8217;s AccessibilityService, or by using multi-stage infection processes and by using package installers that mimic those on Play store to sideload malicious apps, ThreatFabric said.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/mobile-security\/new-wave-of-anatsa-banking-trojan-attacks-targets-android-users-in-europe\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A threat actor is using malware droppers disguised as legitimate<\/p>\n","protected":false},"author":12,"featured_media":2564,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2563","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/new-wave-of-anatsa-banking-trojans-targets-android-users-in-europe.jpg?fit=1000%2C667&ssl=1",1000,667,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/new-wave-of-anatsa-banking-trojans-targets-android-users-in-europe.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/new-wave-of-anatsa-banking-trojans-targets-android-users-in-europe.jpg?fit=300%2C200&ssl=1",300,200,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/new-wave-of-anatsa-banking-trojans-targets-android-users-in-europe.jpg?fit=640%2C427&ssl=1",640,427,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/new-wave-of-anatsa-banking-trojans-targets-android-users-in-europe.jpg?fit=640%2C427&ssl=1",640,427,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/new-wave-of-anatsa-banking-trojans-targets-android-users-in-europe.jpg?fit=1000%2C667&ssl=1",1000,667,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/new-wave-of-anatsa-banking-trojans-targets-android-users-in-europe.jpg?fit=1000%2C667&ssl=1",1000,667,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/new-wave-of-anatsa-banking-trojans-targets-android-users-in-europe.jpg?fit=1000%2C667&ssl=1",1000,667,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/new-wave-of-anatsa-banking-trojans-targets-android-users-in-europe.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/new-wave-of-anatsa-banking-trojans-targets-android-users-in-europe.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/new-wave-of-anatsa-banking-trojans-targets-android-users-in-europe.jpg?fit=1000%2C667&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2563","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2563"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2563\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2564"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2563"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2563"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2563"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}