TrollEye Security

Cyber News

Malicious Apps on Google Play Are Targeting European Android Users With Over 150,000 Downloads

The Anatsa banking trojan has infiltrated the Google Play Store by posing as legitimate apps, racking up over 150,000 downloads while targeting Android users across the UK, Germany, Spain, Slovakia,

Details of The Story

Recently, in a concerning trend, the Anatsa banking trojan has emerged as a formidable threat, exploiting the trust of Android users across Europe. By masquerading as benign applications on the Google Play Store, this malware has orchestrated a sophisticated campaign of deception and infiltration, affecting users in the UK, Germany, Spain, Slovakia, Slovenia, and the Czech Republic over recent months.

This malicious operation has been meticulously crafted, with the attackers deploying dropper apps designed to lure unsuspecting users with the allure of utility and novelty, thus achieving prominence in the “Top New Free” categories on Google Play. The strategic selection of these categories not only amplifies the apps’ visibility but also bestows an unwarranted veneer of legitimacy, significantly enhancing the likelihood of their success. These apps, often disguised as PDF viewers or cleaner apps promising to optimize device performance, are in reality Trojan horses for the Anatsa banking trojan.

The evolution of these dropper apps is particularly alarming. They now employ a multi-stage infection process that cleverly abuses Android’s Accessibility Service, a feature intended to assist users with disabilities, thereby circumventing the security measures in place up to Android 13. This exploitation of accessibility services is a cunning maneuver, leveraging the service’s capabilities to automate the installation of the malicious payload without user consent. This tactic not only demonstrates the adaptability and cunning of cybercriminals but also highlights a significant exploitation vector within Android’s framework that demands urgent and thorough attention.

The revelation that one such app, ‘Phone Cleaner – File Explorer’, amassed over 10,000 downloads before its removal, underscores the scale and effectiveness of this campaign. The persistence of another, a PDF reader app, on the Google Play Store at the time of reporting, with more than 100,000 downloads, serves as a stark reminder of the challenges faced in curbing the spread of such malware.

The reported infection numbers, while already substantial, are likely just the tip of the iceberg. With estimates suggesting actual figures could be closer to 200,000, the impact of Anatsa is both significant and widespread. This situation is exacerbated by the continued release of new dropper apps, each wave refining its methods to evade detection and maximize dissemination.

The technical sophistication of these campaigns cannot be overstated. By employing a multi-staged approach that dynamically downloads malicious components to avoid detection, the operators of Anatsa have demonstrated a high degree of technical acumen. This approach, involving the retrieval of configuration data, the downloading of DEX files containing the malicious code, and the careful orchestration of payload installation, reflects a well-structured and adaptive strategy to maintain the campaign’s momentum while evading the eyes of security mechanisms.

Some steps that we recommend users take include:

Always check the developer’s history and user reviews before downloading an app from Google Play or any other app store. Be wary of new apps with few reviews or a large number of negative feedback.

Review the permissions requested by an app during installation. If an app asks for permissions that seem unnecessary for its stated function (e.g., a PDF reader requesting access to contacts), it could be a red flag.

Stick to apps developed by known, reputable companies. If an app is from an unfamiliar developer, research the developer’s background before downloading.

Regularly update your Android operating system and apps to the latest version to ensure you have the most recent security patches.

Install and maintain security software from a reputable provider on your Android device. These applications can help detect and block malware and other threats.

Be cautious about enabling Accessibility Services for apps unless you are sure of their purpose and legitimacy. Malware often abuses these services to gain control over devices.

Stay informed about the latest malware threats targeting Android users. Awareness can help you recognize potential dangers and act proactively to protect your device.

Regularly back up important data from your Android device. In the event of malware infection, having a backup ensures you don’t lose critical information.

Where possible, enable 2FA for your online accounts. This adds an extra layer of security, making it harder for attackers to gain unauthorized access even if they manage to steal your credentials.

If you encounter an app that you suspect is malicious, report it to Google Play. Your report could help prevent others from becoming victims of malware.

In the face of rising threats like the Anatsa banking trojan, users must prioritize robust security practices like those listed above to safeguard their lives against cyber criminals. By staying informed and critically assessing app legitimacy and permissions, we can protect our personal and financial information from the vulnerabilities of our interconnected world.

Share:

Live Webinar

From Discovery to
Risk Reduction

Operationalizing CTEM in Modern Security Programs

Date September 24, 2026
Time 2:00 PM Eastern

Learn how modern security teams can move beyond finding exposures and operationalize every stage of Continuous Threat Exposure Management.

01 Scope
02 Discover
03 Prioritize
04 Validate
05 Mobilize
Reserve Your Spot

Free registration · Live discussion and Q&A

This Content Is Gated