ThreatFabric researchers have
discovered a new sophisticated campaign by the Anatsa banking trojan targeting mobile banking users in the U.S. and Canada. This is the malware’s third major attack on North American financial institutions.
The latest campaign marks a serious increase in threats, as cybercriminals have breached the official Google Play Store to distribute malware disguised as real apps. Security researchers have revealed that the malware has surpassed 50,000 downloads prior to its detection and subsequent removal.
Anatsa, or TeaBot, is a sophisticated banking trojan that has been under surveillance by cybersecurity experts since 2020. Researchers at ThreatFabric label the Anatsa group as a leading force in mobile crimeware, highlighting their high success rates in various campaigns. The Anatsa campaign uses a strategic multi-stage method to avoid detection.
By infosecbulletin
/ Friday , October 9 2026
There was a rise in scanning and remote code execution attempts on video surveillance devices in Ukraine from September 21...
Read More
By infosecbulletin
/ Thursday , October 8 2026
The FBI and U.S. Secret Service released a joint warning about cybersecurity. The warning said that the FortiBleed campaign is...
Read More
By infosecbulletin
/ Wednesday , October 7 2026
Bangladesh's digital payments system remains severely disrupted after a technology conflict forces core card and interbank services offline for millions...
Read More
By infosecbulletin
/ Tuesday , October 6 2026
Atlassian has fixed CVE-2026-21589, a serious flaw in Atlassian Data Center with a score of 9.3. This bug allows an...
Read More
By infosecbulletin
/ Monday , October 5 2026
Citrix has put out emergency security updates for a NetScaler SAML flaw that hackers are using. Known as CVE-2026-88779, this...
Read More
By infosecbulletin
/ Monday , October 5 2026
Hackers got into the identity and access management system at the Technical University of Denmark (DTU) and downloaded a lot...
Read More
By infosecbulletin
/ Sunday , October 4 2026
Microsoft's official X account was taken over to promote an unapproved Clippy-themed cryptocurrency. The tech giant’s X account, with 13...
Read More
By infosecbulletin
/ Saturday , October 3 2026
CPanel has put out security updates to fix three problems in cPanel & WHM. These problems could let attackers take...
Read More
By infosecbulletin
/ Friday , October 2 2026
Nearly 100,000 Bee Cheng Hiang customers had their email addresses leaked when an employee used an AI tool to generate...
Read More
By infosecbulletin
/ Thursday , October 1 2026
Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. They send special emails that...
Read More
Threat actors create fake developer profiles on Google Play and upload harmless-looking apps like PDF readers and phone cleaners. A harmful PDF reader app reached the top three in the US Google Play Store’s “Top Free Tools” just six weeks after its launch. Security analysis shows that Anatsa uses tricky overlay attacks against banking apps.
When victims attempt to access their mobile banking apps, the malware displays fake maintenance messages reading “Scheduled Maintenance: We are currently enhancing our services and will have everything back up and running shortly. Thank you for your patience.”
The malware can now target over 650 banks worldwide, especially in North America, including JP Morgan, Capital One, TD Bank, and Schwab. The brief distribution from June 24-30 shows how operators effectively cause damage while reducing their risk of detection.
Cybersecurity experts are warning financial institutions to promptly inform customers about the dangers of downloading apps from any source, even official app stores.