Anatsa Banking Trojan Resurfaces, Targets European Banks

The Anatsa banking Trojan campaign has been observed increasingly targeting European banks, according to new data by ThreatFabric researchers.
Since its reemergence in November 2023, the Anatsa campaign has manifested in five distinct waves, targeting various regions, including Slovakia, Slovenia and Czechia, alongside previously affected areas like the UK, Germany and Spain.
Notably, the campaign has evolved its tactics since last year, employing sophisticated methods such as AccessibilityService abuse and multi-staged infection processes.
According to an advisory published by ThreatFabric earlier today, Anatsa's droppers on Google Play have showcased advanced evasion techniques, including dynamic downloading of configuration and malicious executable files from command-and-control servers.
Despite recently bolstered security measures on Google Play, malicious actors persist in exploiting vulnerabilities, as evidenced by the recent resurgence of the Anatsa campaign.
ThreatFabric revealed the worrying use of manufacturer-specific code, mainly targeting Samsung devices, indicating a tailored approach by threat actors.
While presently focused on Samsung, future adaptations are possible to target other manufacturers, underscoring the necessity for vigilance across all device types.
The campaign's execution flow unveils intricate layers of evasion tactics, including the circumvention of Android 13 restrictions, accentuating the sophistication of contemporary mobile malware.
Financial institutions are urged to educate customers about the risks associated with installing applications from official stores and enabling AccessibilityService unnecessarily.
With over 100,000 total installations across five droppers in the current campaign, the threat posed by Anatsa remains significant, highlighting the importance of continuous monitoring and proactive security measures.


This Cyber News was published on www.infosecurity-magazine.com. Publication date: Mon, 19 Feb 2024 17:20:50 +0000


Cyber News related to Anatsa Banking Trojan Resurfaces, Targets European Banks

Anatsa Banking Trojan Resurfaces, Targets European Banks - The Anatsa banking Trojan campaign has been observed increasingly targeting European banks, according to new data by ThreatFabric researchers. Since its reemergence in November 2023, the Anatsa campaign has manifested in five distinct waves, ...
1 year ago Infosecurity-magazine.com
Over 90 malicious Android apps with 5.5M installs found on Google Play - Over 90 malicious Android apps were found installed over 5.5 million times through Google Play to deliver malware and adware, with the Anatsa banking trojan seeing a recent surge in activity. Anatsa is a banking trojan that targets over 650 ...
1 year ago Bleepingcomputer.com
Anatsa Android Banking Malware from Google Play Targeting Users in the U.S. and Canada - ThreatFabric researchers have identified a sophisticated new campaign by the Anatsa banking trojan specifically targeting mobile banking customers across the United States and Canada, marking the malware’s third major offensive against North ...
1 month ago Cybersecuritynews.com
Android malware Anatsa infiltrates Google Play to target US banks - According to Threat Fabric researchers who spotted the latest campaign and reported it to Google, Anatsa shows users a fake message when they open the targeted apps, informing of a scheduled banking system maintenance. Anatsa periodically finds ways ...
1 month ago Bleepingcomputer.com
How Banks Can Adapt to the Rising Threat of Financial Crime - To combat this, banks need to implement advanced AI-driven fraud monitoring and detection tools, enhance identity verification processes, and stay vigilant with continuous monitoring and staff training to recognize anomalies. While most banks ...
5 months ago Darkreading.com
New Wave of 'Anatsa' Banking Trojans Targets Android Users in Europe - The campaign has been ongoing for at least four months and is the latest salvo from the operators of the malware, which first surfaced in 2020 and has previously notched victims in the US, Italy, United Kingdom, France, Germany, and other countries. ...
1 year ago Darkreading.com
29 malware families target 1,800 banking apps worldwide - Mobile banking is outpacing online banking across all age groups due to its convenience and our desire to have those apps at our fingertips, according to Zimperium. This surge is accompanied by a dramatic growth in financial fraud. The research ...
1 year ago Helpnetsecurity.com
Ten new Android banking trojans targeted 985 bank apps in 2023 - This year has seen the emergence of ten new Android banking malware families, which collectively target 985 bank and fintech/trading apps from financial institutes across 61 countries. Banking trojans are malware that targets people's online bank ...
1 year ago Bleepingcomputer.com
Android App With 220,000+ Downloads From Google Play Installs Banking Trojan - A sophisticated Android banking trojan campaign leveraging a malicious file manager application accumulated over 220,000 downloads on the Google Play Store before its removal. According to the Zscaler ThreatLabz post shared on X, the malicious app, ...
5 months ago Cybersecuritynews.com
Android malware and unwanted software statistics for Q1 2024 - Over 389,000 malicious installation packages were detected, of which: 11,729 packages were related to mobile banking Trojans, 1,990 packages were mobile ransomware Trojans. The rapid growth in the total number of attacks between Q2 and Q4 2023 is ...
1 year ago Securelist.com
Lampion Banking Malware Employs ClickFix Lures To Steal Banking Information - Once executed, the malware begins its covert operation to harvest banking credentials, credit card information, and other sensitive financial data from compromised systems. A sophisticated banking trojan known as Lampion has resurfaced with an ...
3 months ago Cybersecuritynews.com
Microsoft Cloud Users Store Personal Data In Europe - In effort to resolve privacy worries, Microsoft is to allow its cloud customers to store all personal data within EU. Microsoft has confirmed that it will allow cloud customers to store all their personal data within the European Union, in an effort ...
1 year ago Silicon.co.uk
PixPirate: New Android Banking Trojan Targeting Brazilian Financial Institutions - A new Android banking trojan has set its eyes on Brazilian financial institutions to commit fraud by leveraging the PIX payments platform. Italian cybersecurity company Cleafy, which discovered the malware between the end of 2022 and the beginning of ...
2 years ago Thehackernews.com
Over 100 European Banks Face Cyber Resilience Test - Over 100 European banks will be tested on their cyber-attack response and recovery capabilities this year, the European Central Bank has announced. The EU's central bank will conduct its first ever cyber resilience stress test on 109 directly ...
1 year ago Infosecurity-magazine.com
ToxicPanda Android Banking Malware Infected 4500+ Devices to Steal Banking Credentials - A sophisticated Android banking trojan known as ToxicPanda has successfully infiltrated over 4500 mobile devices across Europe, representing one of the most significant mobile banking malware campaigns observed in recent years. The malware shows ...
1 week ago Cybersecuritynews.com
New Banking Malware DoubleTrouble Attacking Users Via Phishing Sites To Steal Banking Credentials - DoubleTrouble represents a concerning evolution in mobile banking malware, combining traditional overlay attacks with cutting-edge capabilities including comprehensive screen recording, advanced keylogging, and real-time device manipulation. ...
1 week ago Cybersecuritynews.com
7th Cybersecurity Forum: Power grids cybersecurity ascending to prominence — ENISA - 7th Cybersecurity Forum: Power grids cybersecurity ascending to prominence The Association of European Distribution System Operators (E.DSO), the European Energy Information Sharing and Analysis Centre (EE-ISAC), the European Network for Cyber ...
10 months ago Enisa.europa.eu
Ransomware Attack on Banks Costs an Average of $6.08 Million Along With Downtime & Reputation Loss - Financial institutions can significantly reduce their risk exposure by implementing comprehensive security awareness training and regularly testing their incident response capabilities against simulated banking-specific ransomware scenarios. What ...
3 months ago Cybersecuritynews.com
Beware, iPhone Users: iOS GoldDigger Trojan can Steal Face ID and Banking Details - Numerous people pick iPhones over Android phones because they believe iPhones are more secure. This may no longer be the case due to the emergence of a new banking trojan designed explicitly to target iPhone users. According to a detailed report by ...
1 year ago Cysecurity.news
New Grandoreiro Malware Variant Targets Spain - Cybersecurity experts at Proofpoint have identified a new variant of the Grandoreiro malware, previously known for targeting victims in Brazil and Mexico. This latest version of Grandoreiro, attributed to the threat actor TA2725, has expanded its ...
1 year ago Infosecurity-magazine.com
Undetected Android Trojan Expands Attack on Iranian Banks - Security researchers have uncovered the continuation and expansion of an Android mobile banking Trojan campaign targeting major Iranian banks. Initially discovered in July 2023, the campaign has not only persisted but has also evolved with enhanced ...
1 year ago Infosecurity-magazine.com
Third Of European Businesses Have Adopted AI, AWS - AWS finds AI already adopted at sizeable number of European businesses, resulting in increased revenues, productivity. An insight into the adoption rate of artificial intelligence within the business community has been offered in a new report from ...
1 year ago Silicon.co.uk
Cybercriminals expand targeting of Iranian bank customers with known mobile malware - Researchers have uncovered more than 200 fake mobile apps that mimic major Iranian banks to steal information from their customers. The campaign was first discovered in July of this year, but since then, the cybercriminals have expanded their ...
1 year ago Therecord.media
RBI Has Mandated That All Bank Websites in India migrate to the .bank.in  - This landmark cybersecurity initiative aims to create a more secure digital banking ecosystem and combat the rising threat of phishing attacks targeting Indian banking customers. Cybersecurity experts estimate that phishing attacks targeting Indian ...
3 months ago Cybersecuritynews.com
Cybersecurity Risk to Banking Sector a Significant Challenge: RBI Governor - As cybersecurity concerns become a challenge, India's banking system is well-positioned to sustain the nation's growth, as Reserve Bank of India governor Shaktikanta Das stated earlier this week. He noted at the Mint BFSI conclave that a dedicated ...
1 year ago Cysecurity.news