Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    It’s time we blow up PC benchmarking

    If my Wi-Fi’s not working, here’s how I find answers

    Asus ROG NUC 2025 review: Mini PC in size, massive in performance

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Blue-collar jobs are gaining popularity as AI threatens office work

      August 17, 2025

      Man who asked ChatGPT about cutting out salt from his diet was hospitalized with hallucinations

      August 15, 2025

      What happens when chatbots shape your reality? Concerns are growing online

      August 14, 2025

      Scientists want to prevent AI from going rogue by teaching it to be bad first

      August 8, 2025

      AI models may be accidentally (and secretly) learning each other’s bad behaviors

      July 30, 2025
    • Business

      Why Certified VMware Pros Are Driving the Future of IT

      August 24, 2025

      Murky Panda hackers exploit cloud trust to hack downstream customers

      August 23, 2025

      The rise of sovereign clouds: no data portability, no party

      August 20, 2025

      Israel is reportedly storing millions of Palestinian phone calls on Microsoft servers

      August 6, 2025

      AI site Perplexity uses “stealth tactics” to flout no-crawl edicts, Cloudflare says

      August 5, 2025
    • Crypto

      Japan Auto Parts Maker Invests US Stablecoin Firm and Its Stock Soars

      August 29, 2025

      Stablecoin Card Firm Rain Raise $58M from Samsung and Sapphire

      August 29, 2025

      Shark Tank Star Kevin O’Leary Expands to Bitcoin ETF

      August 29, 2025

      BitMine Stock Moves Opposite to Ethereum — What Are Analysts Saying?

      August 29, 2025

      Argentina’s Opposition Parties Reactivate LIBRA Investigation Into President Milei

      August 29, 2025
    • Technology

      It’s time we blow up PC benchmarking

      August 29, 2025

      If my Wi-Fi’s not working, here’s how I find answers

      August 29, 2025

      Asus ROG NUC 2025 review: Mini PC in size, massive in performance

      August 29, 2025

      20 free ‘hidden gem’ apps I install on every Windows PC

      August 29, 2025

      Lowest price ever: Microsoft Office at $25 over Labor Day weekend

      August 29, 2025
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»Malicious Android apps with 19M installs removed from Google Play
    Technology

    Malicious Android apps with 19M installs removed from Google Play

    TechAiVerseBy TechAiVerseAugust 26, 2025No Comments4 Mins Read2 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Malicious Android apps with 19M installs removed from Google Play
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    BMI Calculator – Check your Body Mass Index for free!

    Malicious Android apps with 19M installs removed from Google Play

    Seventy-seven malicious Android apps with more than 19 million installs were delivering multiple malware families to Google Play users.

    This malware infiltration was discovered by Zscaler’s ThreatLabs team while investigating a new infection wave with Anatsa (Tea Bot) banking trojan targeting Android devices.

    While most of the malicious apps (over 66%) included adware components, the most common Android malware was Joker, which researchers encountered in almost 25% of the analyzed apps.

    Once Joker malware is installed on a device, it can read and send text messages, take screenshots, make phone calls, and steal contact lists, access device information, and subscribe users to premium services.

    A smaller percentage of the apps included maskware, a term used to define a malicious app that disguises itself as something that would not raise any suspicion.

    This type of malware may pose as a legitimate app that works as advertised. However, it performs malicious activity in the background, such as steal credentials, banking info, or other sensitive data (location, SMS). Cybercriminals can also use maskware to deliver other malware.

    Zscaler researchers also found a variant of the Joker malware called Harly, which comes as a legitimate app that has a malicious payload hidden deeper in the code to avoid detection during the review process.

    Caption

    In a report in March, Human Security researchers said that Harly can hide in popular apps, like games, wallpapers, flashlights, and photo editors.

    Anatsa trojan keeps evolving

    According to Zscaler, the latest version of the Anatsa banking trojan has further expanded its targeting scope, increasing the number of banking and cryptocurrency apps to 831, from 650 previously, that it attempts to steal data from.

    The malware operators use an app named ‘Document Reader – File Manager’ as a decoy, which only downloads the malicious Anatsa payload after installation, to evade Google’s code review.

    Anatsa trojan app on Google Play
    Source: Zscaler

    The latest campaign has switched from remote DEX dynamic code loading used in the past to direct payload installation, unpacking it from JSON files, and then deleting them.

    In terms of evasion, it uses malformed APK archives to break static analysis, runtime DES-based string decryption, and emulation detection. Package names and hashes are also periodically changed.

    Detecting emulation (left) and fetching the payload (right)
    Source: Zscaler

    Capability-wise, Anatsa abuses Accessibility permissions on Android to auto-grant itself extensive privileges.

    It fetches phishing pages from its server for over 831 apps, now also covering Germany and South Korea, while a keylogger module has also been added for generic data theft.

    This latest Anatsa campaign follows another recent wave discovered by ThreatFabric in July, where the trojan sneaked into Google Play posing as a PDF viewer, achieving over 50,000 downloads.

    Older Anatsa campaigns include a PDF and QR Code Reader attack in May 2024 that achieved 70,000 infections, a Phone Cleaner and PDF attack in February 2024 that got 150,000 downloads, and another PDF Viewer attack in March 2023 that achieved 30,000 installs.

    Malicious app wave on Google Play

    In addition to the malicious Anatsa apps, Zscaler discovered this time, most were adware families, followed by ‘Joker,’ ‘Harly,’ and various maskware.

    “ThreatLabz identified a sharp rise in adware applications on the Google Play Store alongside malware, such as Joker, Harly, and banking trojans like Anatsa,” explained Zscaler researcher Himanshu Sharma

    “Conversely, there has been a noticeable decline in malware families such as Facestealer and Coper.”

    Tools and personalization apps accounted for over half of the lures used to spread those apps, so these two categories, together with entertainment, photography, and design, should be treated as high-risk.

    In total, the 77 malicious apps, including those containing Anatsa, were downloaded 19 million times from Google Play.

    Zscaler reports that Google removed all of the malicious apps they discovered this time from the Play Store following their reporting.

    Android users must ensure their Play Protect service is active on their device to flag malicious apps for removal.

    In the case of Anatsa trojan infections, separate steps need to be taken with the bank to protect potentially compromised e-banking accounts or credentials.

    To minimize the risk from malware loaders on Google Play, only trust reputable publishers, read at least a couple of user reviews, and only grant permissions that are directly related to the app’s core functionality.


    BMI Calculator – Check your Body Mass Index for free!

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleI saw Samsung’s $30,000, 115-inch micro-RGB TV, and its vivid picture outshines mini-LED TVs
    Next Article Auchan retailer data breach impacts hundreds of thousands of customers
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    It’s time we blow up PC benchmarking

    August 29, 2025

    If my Wi-Fi’s not working, here’s how I find answers

    August 29, 2025

    Asus ROG NUC 2025 review: Mini PC in size, massive in performance

    August 29, 2025
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025166 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 202548 Views

    New Akira ransomware decryptor cracks encryptions keys using GPUs

    March 16, 202530 Views

    Is Libby Compatible With Kobo E-Readers?

    March 31, 202528 Views
    Don't Miss
    Technology August 29, 2025

    It’s time we blow up PC benchmarking

    It’s time we blow up PC benchmarking Image: Willis Lai / Foundry Welcome to The…

    If my Wi-Fi’s not working, here’s how I find answers

    Asus ROG NUC 2025 review: Mini PC in size, massive in performance

    20 free ‘hidden gem’ apps I install on every Windows PC

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    It’s time we blow up PC benchmarking

    August 29, 20252 Views

    If my Wi-Fi’s not working, here’s how I find answers

    August 29, 20251 Views

    Asus ROG NUC 2025 review: Mini PC in size, massive in performance

    August 29, 20252 Views
    Most Popular

    Xiaomi 15 Ultra Officially Launched in China, Malaysia launch to follow after global event

    March 12, 20250 Views

    Apple thinks people won’t use MagSafe on iPhone 16e

    March 12, 20250 Views

    French Apex Legends voice cast refuses contracts over “unacceptable” AI clause

    March 12, 20250 Views
    © 2025 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.