Ce redoutable malware est de retour sur Android, et il veut vider votre compte en banque
Recent discoveries have identified Anatsa as a threat affecting various sectors, including German and South Korean banks, as well as cryptocurrency platforms. This malware utilizes deceptive applications on the Play Store, masquerading as document…
Recent discoveries have identified Anatsa as a threat affecting various sectors, including German and South Korean banks, as well as cryptocurrency platforms. This malware utilizes deceptive applications on the Play Store, masquerading as document readers or utility apps. Some of these applications have exceeded 50,000 downloads before being detected.
Researchers have employed continuous analysis of suspicious applications available on the official Google store. This method allows for monitoring malicious campaign trends and promptly identifying new threats. ThreatLabz has reported 77 infected applications to Google, with a total of over 19 million installations.
Recent observations indicate that Anatsa has transitioned from downloading malicious code dynamically to directly installing a full viral payload. This payload is encrypted in real-time using an on-the-fly generated key, complicating security tool analysis. The malware further inspects the device model to detect if it operates in an emulation environment designed for analysis.
If the target device appears legitimate, Anatsa downloads its payload from a command server. Otherwise, the app presents an ordinary file manager interface, maintaining an appearance of legitimacy. To further obfuscate its presence, the package name and installation fingerprint are regularly altered.
This malware utilizes deceptive applications on the Play Store, masquerading as document readers or utility apps.
The latest version incorporates a keylogger to capture user keystrokes. Banking credentials are stolen through fake login pages mimicking targeted banks. These pages are dynamically downloaded from the malicious server, adapting based on the applications detected on the infected smartphone.
Anatsa's presence on the Play Store highlights the challenges in completely eradicating such malware. Despite Google's security measures, cybercriminals continually find ways to bypass defenses and distribute their malicious software. ThreatLabz reports a notable increase in adware applications, while other malware families like Facestealer and Coper are declining.
Users must remain vigilant, ensuring to verify app permissions before installation, particularly those requesting access to sensitive functions like SMS, notifications, or accessibility services. Once installed with appropriate permissions, Anatsa can lock devices, read and intercept messages, and display malicious overlays on top of legitimate applications.
D’après Journal du Geek.
