Malicious PDF Reader With 10,000+ Installs on Google Play Delivers Anatsa Banking Trojan

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A malicious Android PDF reader distributed through Google Play has recorded more than 10,000 installs while serving as an installer for the Anatsa banking trojan.

The finding shows how a routine document tool can become a route for malware that puts banking passwords and financial accounts at risk.

The installation figure describes the reach of the reader app, not a confirmed count of successful banking infections or stolen accounts.

The available alert also does not identify affected banks, victim countries, financial losses, or whether Google has since removed this particular listing, wile those details remain unconfirmed.

Researchers from Zscaler ThreatLabz identified the malicious installer and shared its indicators in an October 8 alert on X.

They described the application as an Android PDF reader with over 10,000 installs and published separate file hashes for the installer and the Anatsa payload, alongside their command-and-control addresses.

The discovery follows earlier cases involving similar disguises. In April, a fake document reader campaign used a different package to distribute Anatsa before Google removed that app.

That earlier removal should not be confused with the status of the newly reported reader, which the current alert does not establish.

Malicious PDF Reader With 10,000+ Installs

Anatsa, also known as TeaBot, uses a dropper model: the app installed first acts as a delivery tool for a separate malicious component.

This separation helps explain why a download that appears useful can later expose a phone to banking malware. The latest alert identifies both stages but does not provide a full execution trace.

In its technical analysis of Anatsa, ThreatLabz documented earlier campaigns that downloaded additional code and presented the final payload as an app update.

Some samples checked the device environment before proceeding, helping the malware avoid test systems used by researchers. These are documented family techniques, not confirmed findings for every new sample.

ThreatLabz also documented malformed APK archive headers that made older payloads harder to inspect, along with encrypted code loaded at runtime.

APK files are Android installation packages; hiding their contents can disrupt tools that inspect files without running them. The new alert does not confirm whether these samples use those methods.

The broader use of Google Play stealth loaders shows why unexpected update requests deserve attention even when the original app came from an official store.

A request to install an extra component outside the normal update process can move the user from a harmless-looking utility to the banking payload.

For this campaign, ThreatLabz listed one installer-related command-and-control URL and two payload command-and-control endpoints.

Keeping those roles separate matters during an investigation: the installer and the banking trojan are different files, and each has its own published MD5 hash. The alert does not explain the exact contents returned by the installer URL.

Why Banking Accounts Are at Risk

Earlier ThreatLabz research found that Anatsa requested SMS and accessibility permissions, contacted its control server, and checked for targeted financial apps.

The server then supplied fake login pages matching apps on the phone. Credentials entered into those pages were sent to the attackers rather than the bank.

A previous Anatsa document reader outbreak reached more than 100,000 downloads and used fake banking screens to capture account details.

That history explains the concern around this new reader, but its target list and permission behavior still require sample-specific verification rather than assumptions based on older campaigns.

What Android Users Should Do

Users who installed the identified reader should remove it, review granted permissions, and scan their phones with a trusted security tool.

Keep Google Play Protect enabled and question unexpected requests for SMS or accessibility access. If banking activity looks suspicious, contact the bank promptly and change account passwords from a trusted device.

For security teams, the package name can support app inventory checks, while file hashes help match samples against the reported installer and payload.

Network logs can be searched for the listed domain and IP endpoints. Matches should be reviewed in context to establish which device communicated, when contact occurred, and whether malware executed.

Indicators of compromise (IoCs):-

Type Indicator Role
Package com.railforge.footplate.documentreader_pdfviewer Reader installer
Store URL play.google[.]com/store/apps/details?id=com.railforge.footplate.documentreader_pdfviewer Google Play listing
MD5 152d8649a03667dbf4b94312d185c41d Installer hash
C2 URL https://railforgefootplate[.]com/disclaimers.txt Installer endpoint
MD5 2451fae883ec7a4e7876d6abe486e1eb Payload hash
C2 URL http://193.24.123[.]18:85/api/ Payload endpoint
C2 URL http://162.252.173[.]37:85/api/ Payload endpoint

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post Malicious PDF Reader With 10,000+ Installs on Google Play Delivers Anatsa Banking Trojan appeared first on Cyber Security News.