s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.anatsa

📛 Threat Title

Malware family: Anatsa

Category: Anatsa First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.anatsa`. Printable name: Anatsa. Aliases: ReBot,TeaBot,Toddler.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.anatsa VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.anatsa

IOC database

Type
domain
Value
apk.anatsa
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.anatsa

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.anatsa

References (1)

Remediations (10)

  • web:blog.netmanageit.com

    5. Mitigation Strategies for Organizations and Users To defend against Anatsa and similar banking trojans, organizations should enforce strict application whitelisting policies, utilize runtime behavioral analysis, and deploy emulation-resistant scanning solutions.

  • web:cyberpress.org

    Cybersecurity researchers at Zscaler ThreatLabz have uncovered significant developments in the Anatsa banking malware , revealing that the Android trojan has expanded its targeting scope to over 831 financial institutions worldwide while implementing sophisticated anti-analysis techniques to evade detection.

  • web:cybersecuritynews.com

    Security researchers report that the malware has already achieved over 50,000 downloads before detection and removal. Sophisticated Device Takeover Capabilities Anatsa , also known as TeaBot, is a highly sophisticated banking trojan that has been actively monitored by cybersecurity experts since 2020.

  • web:infosecbulletin.com

    The latest campaign marks a serious increase in threats, as cybercriminals have breached the official Google Play Store to distribute malware disguised as real apps. Security researchers have revealed that the malware has surpassed 50,000 downloads prior to its detection and subsequent removal. Anatsa , or TeaBot, is a sophisticated banking trojan that has been under surveillance by ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Anatsa malware family including references, samples and yara signatures.

  • web:www.bsi.bund.de

    Additionally, the malware is capable of stealing cryptocurrencies and exfiltrating various information about the victim. How did I get infected with Anatsa ? Currently, Anatsa is being distributed through disguised Android applications in the official Google Play Store.

  • web:www.incibe.es

    An IOC rule and a Yara rule are also available in this analysis to assist in the detection of samples belonging to this malware family . The technical report includes:

  • web:www.threatfabric.com

    Anatsa Trojan Returns: Targeting Europe and Expanding Its Reach 19 February 2024 Introduction In the dynamic world of mobile banking, the security landscape is constantly shifting, posing new challenges for banks and financial institutions. It is therefore imperative to stay ahead of emerging threats.

  • web:www.tomsguide.com

    The Anatsa banking trojan was recently discovered hiding in a malicious app as part of a new campaign that uses the malware to drain bank accounts.

  • web:www.zscaler.com

    This analysis explores the latest updates to the Anatsa Android malware family .

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.