TF-MAL-apk.anatsa
📛 Threat Title
Malware family: Anatsa
Description
ThreatFox malware family `apk.anatsa`. Printable name: Anatsa. Aliases: ReBot,TeaBot,Toddler.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.anatsa
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.anatsa
IOC database
- Type
- domain
- Value
apk.anatsa- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.anatsa
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.anatsa
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:blog.netmanageit.com
5. Mitigation Strategies for Organizations and Users To defend against Anatsa and similar banking trojans, organizations should enforce strict application whitelisting policies, utilize runtime behavioral analysis, and deploy emulation-resistant scanning solutions.
-
web:cyberpress.org
Cybersecurity researchers at Zscaler ThreatLabz have uncovered significant developments in the Anatsa banking malware , revealing that the Android trojan has expanded its targeting scope to over 831 financial institutions worldwide while implementing sophisticated anti-analysis techniques to evade detection.
-
web:cybersecuritynews.com
Security researchers report that the malware has already achieved over 50,000 downloads before detection and removal. Sophisticated Device Takeover Capabilities Anatsa , also known as TeaBot, is a highly sophisticated banking trojan that has been actively monitored by cybersecurity experts since 2020.
-
web:infosecbulletin.com
The latest campaign marks a serious increase in threats, as cybercriminals have breached the official Google Play Store to distribute malware disguised as real apps. Security researchers have revealed that the malware has surpassed 50,000 downloads prior to its detection and subsequent removal. Anatsa , or TeaBot, is a sophisticated banking trojan that has been under surveillance by ...
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Anatsa malware family including references, samples and yara signatures.
-
web:www.bsi.bund.de
Additionally, the malware is capable of stealing cryptocurrencies and exfiltrating various information about the victim. How did I get infected with Anatsa ? Currently, Anatsa is being distributed through disguised Android applications in the official Google Play Store.
-
web:www.incibe.es
An IOC rule and a Yara rule are also available in this analysis to assist in the detection of samples belonging to this malware family . The technical report includes:
-
web:www.threatfabric.com
Anatsa Trojan Returns: Targeting Europe and Expanding Its Reach 19 February 2024 Introduction In the dynamic world of mobile banking, the security landscape is constantly shifting, posing new challenges for banks and financial institutions. It is therefore imperative to stay ahead of emerging threats.
-
web:www.tomsguide.com
The Anatsa banking trojan was recently discovered hiding in a malicious app as part of a new campaign that uses the malware to drain bank accounts.
-
web:www.zscaler.com
This analysis explores the latest updates to the Anatsa Android malware family .
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.