In case you missed it: Bank info-stealing malware found in 90+ Android apps with 5.5M installs

The apps identified have since been removed from Google Play, but make sure you didn't install one.
By Cecily Mauran  on 
unauthorized credit card alert on an android screen
The malware was disguised as PDF and QR code readers. Credit: Thai Liang Lim / iStock / Getty Images Plus / Getty Images

A report from cybersecurity firm Zscaler has discovered over 90 malicious Android apps uploaded to Google Play over the past few months, including a particularly sophisticated trojan called Anatsa.

Collectively, the malware apps have been installed over 5.5 million times.

How Anatsa malware tries to fool Android users

As of Thursday, Google has banned the apps identified in the report, according to BleepingComputer. Anatsa, also known as "TeaBot," and other malware in the report, are dropper apps that masquerade as PDF and QR code readers, photography, and health and fitness apps. As the outlet reported, the findings demonstrate the "high risk of malicious dropper apps slipping through the cracks in Google's review process."

Mashable Light Speed
Want more out-of-this world tech, space and science stories?
Sign up for Mashable's weekly Light Speed newsletter.
By signing up you agree to our Terms of Use and Privacy Policy.
Thanks for signing up!

Although Anatsa only accounts for around two percent of the most popular malware, it does a lot of damage. It's known for targeting over 650 financial institutions — and two of its PDF and QR code readers had both amassed over 70,000 downloads at the time the report was published.

Once installed as a seemingly legitimate app, Anatsa uses advanced techniques to avoid detection and gain access to banking information. The two apps mentioned in the report were called "PDF Reader and File Manager" by Tsarka Watchfaces and "QR Reader and File Manager" by risovanul. So, they definitely have an innocuous look to unsuspecting Android users.

The majority of apps containing the malware were classified as tools like file managers, editors, and translators. Other categories of apps included photography, productivity, and "personalization," which was unspecified, but might include apps for customizing Android home screens and wallpaper.

These malware-infected apps may have been taken down, but it's an uneasy reminder to remain vigilant about which apps you're installing.

Mashable Image
Cecily Mauran

Cecily is a tech reporter at Mashable who covers AI, Apple, and emerging tech trends. Before getting her master's degree at Columbia Journalism School, she spent several years working with startups and social impact businesses for Unreasonable Group and B Lab. Before that, she co-founded a startup consulting business for emerging entrepreneurial hubs in South America, Europe, and Asia. You can find her on Twitter at @cecily_mauran.


Recommended For You
New Mac malware 'Cuckoo' can take screenshots of your desktop and other creepy actions
MacBook on a table



Webb found its strongest case yet of a rocky exoplanet with an atmosphere
Webb studying rocky exoplanet

Amazon deal of the day: Introduce your kiddos to Alexa with 45% off the Echo Dot Kids
Lenovo tablet, Anker charger, Tile Mate, and Echo Dot Kids with purple background

Trending on Mashable
Wordle today: Here's the answer hints for July 31
a phone displaying Wordle

NYT Connections today: See hints and answers for July 31
A phone displaying the New York Times game 'Connections.'

Webb telescope snapped photo of huge world — in a distant solar system
An illustration of the James Webb Space Telescope as it orbits the sun in our solar system, 1 million miles from Earth.

All the best places to click on when you want to get off
pornhub Logo

NYT Strands hints, answers for July 31
A game being played on a smartphone.
The biggest stories of the day delivered to your inbox.
This newsletter may contain advertising, deals, or affiliate links. Subscribing to a newsletter indicates your consent to our Terms of Use and Privacy Policy. You may unsubscribe from the newsletters at any time.
Thanks for signing up. See you at your inbox!