ThreatFabric researchers have
discovered a new sophisticated campaign by the Anatsa banking trojan targeting mobile banking users in the U.S. and Canada. This is the malware’s third major attack on North American financial institutions.
The latest campaign marks a serious increase in threats, as cybercriminals have breached the official Google Play Store to distribute malware disguised as real apps. Security researchers have revealed that the malware has surpassed 50,000 downloads prior to its detection and subsequent removal.
Anatsa, or TeaBot, is a sophisticated banking trojan that has been under surveillance by cybersecurity experts since 2020. Researchers at ThreatFabric label the Anatsa group as a leading force in mobile crimeware, highlighting their high success rates in various campaigns. The Anatsa campaign uses a strategic multi-stage method to avoid detection.
By infosecbulletin
/ Saturday , July 18 2026
A new free tool is adding AI helpers into security work. PentestCode is a version of OpenCode made just for...
Read More
By infosecbulletin
/ Saturday , July 18 2026
The WordPress security team received reports about these flaws: CVE-2026-60137 : A facilitated SQL injection issue reported as a team...
Read More
By infosecbulletin
/ Friday , July 17 2026
A Windows security flaw called LegacyHive (MSNightmare) misuses the User Profile Service. This allows local users to gain higher privileges,...
Read More
By infosecbulletin
/ Thursday , July 16 2026
Zoom has issued updates for a flaw in the Windows desktop client, known as CVE-2026-53412. This issue may allow an...
Read More
By infosecbulletin
/ Thursday , July 16 2026
India is speeding up its work to make homegrown AI models for cybersecurity. These models will help protect important digital...
Read More
By infosecbulletin
/ Wednesday , July 15 2026
A serious security flaw in Cursor, a popular AI code editor used by more than 7 million developers, lets attackers...
Read More
By infosecbulletin
/ Wednesday , July 15 2026
Microsoft's Patch Tuesday in July 2026 fixes around 570 security flaws in its products. This comes after June's big update,...
Read More
By infosecbulletin
/ Wednesday , July 15 2026
Fortinet fixes seven new security warnings on July 14, 2026. These affect FortiOS, FortiProxy, FortiPAM, and FortiSandbox. The issues vary...
Read More
By infosecbulletin
/ Tuesday , July 14 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that hackers are using CVE-2008-4128, a CSRF flaw in Cisco...
Read More
By infosecbulletin
/ Tuesday , July 14 2026
Meta announced on Monday that its data center in Richland Parish, Louisiana, will grow to 5 gigawatts of computing power....
Read More
Threat actors create fake developer profiles on Google Play and upload harmless-looking apps like PDF readers and phone cleaners. A harmful PDF reader app reached the top three in the US Google Play Store’s “Top Free Tools” just six weeks after its launch. Security analysis shows that Anatsa uses tricky overlay attacks against banking apps.
When victims attempt to access their mobile banking apps, the malware displays fake maintenance messages reading “Scheduled Maintenance: We are currently enhancing our services and will have everything back up and running shortly. Thank you for your patience.”
The malware can now target over 650 banks worldwide, especially in North America, including JP Morgan, Capital One, TD Bank, and Schwab. The brief distribution from June 24-30 shows how operators effectively cause damage while reducing their risk of detection.
Cybersecurity experts are warning financial institutions to promptly inform customers about the dangers of downloading apps from any source, even official app stores.