Anatsa, also widely known as TeaBot and sometimes Toddler, is an Android banking trojan focused on stealing financial credentials and enabling on-device fraud. First publicly identified in 2021 after emerging around 2020, it has repeatedly been distributed through trojanized Android applications, including apps placed on Google Play that masquerade as utilities such as document readers, PDF tools, QR scanners, cryptocurrency tools, and similar productivity software. Delivery has also been observed through international smishing campaigns using parcel-delivery lures and fake update prompts that stage the second-stage payload after the initial app appears benign.
Once active, Anatsa abuses Android Accessibility Services and related high-risk permissions to monitor application activity, log keystrokes, collect device and contact information, and inspect screen content. It detects when targeted financial applications are opened and deploys credential-stealing overlays that imitate legitimate login interfaces. Beyond classic overlay theft, Anatsa supports accessibility logging that can expose visible UI content and user interactions, enabling operators to understand app flows and harvest sensitive data. Reported command support also shows remote-access functionality that allows operators to observe the victim screen in real time, perform clicks and other UI actions, open applications, manipulate text input, and steal authenticator codes, making the malware suitable for direct fraud execution from the victim device.
Anatsa has been described as an advanced Android banking threat with RAT and semi-ATS capabilities. Its operators have used staged droppers and selective payload delivery to reduce exposure during app-store review, sometimes keeping first-stage apps largely benign until a later malicious update or conditional activation. Recent variants have also used anti-analysis and obfuscation techniques, including runtime decryption and environment checks, to hinder detection and reverse engineering.
The malware has targeted a large global set of financial applications, including banking, investment, and cryptocurrency services, with reporting citing hundreds of institutions worldwide. Campaigns have affected multiple regions, including Europe, and Anatsa has periodically re-emerged after temporary declines in activity. It is regarded as one of the more mature Android banking malware families because it combines credential theft, surveillance of user activity, and remote device interaction to support full account takeover and fraudulent transactions from a trusted mobile context.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Anatsa was discovered by ThreatFabric in January 2021. Anatsa is a rather advanced Android banking trojan with RAT and semi-ATS capabilities.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
decrypts the malicious payload file called eepHM.json from the app’s assets folder to an executable dex format named ‘eepHM.odex’ and loads the decrypted file
These apps posed as QR code scanners, PDF scanners, and cryptocurrency apps.
This malware also terminates the predefined list of apps process(es)... that list includes a few popular security products... in order to remain undetected.
this malicious apk decrypts the malicious payload file called kbu.json from the app’s assets folder to an executable dex format named ‘kbu.odex’ and loads the decrypted file
the configuration contains filter rules based on device model. Based on the models being filtered out and the code of the dropper, we can draw a conclusion that this is done to avoid downloading the payload on emulators or research environment.
This is a classic Android bot, equipped with credential stealing capabilities such as the use of overlays (fake login screens) for crypto-currency wallet apps and Android banking apps.
Other features include keylogging, contact information and device information exfiltration, and accessibility logging.
the malware C2 sends the specific payload(s) to the victim device to perform an overlay attack and track all the activity related to the identified targeted application(s).
This is a classic Android bot, equipped with credential stealing capabilities such as the use of overlays (fake login screens) for crypto-currency wallet apps and Android banking apps.
Other features include keylogging, contact information and device information exfiltration, and accessibility logging.
The PTI team has de-anonymized the C&C server and discovered that Toddler has already infected more than 7,632 devices at the time of this report.
it's also designed to retrieve a malicious APK file hosted on GitHub
39 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan delivered via malicious Google Play loader apps using fake update prompts; once installed, it seeks information that can help criminals access financial accounts or approve fraudulent activity.
Android banking malware delivered via trojanized apps on Google Play; it uses a fake update prompt to install the banking Trojan on victims’ devices.
Android banking trojan delivered via a malicious loader embedded in a Google Play PDF viewer app; the app displayed a fake update prompt that actually downloaded the trojan.
Android banking malware delivered via trojanized Google Play apps; it uses a fake update prompt to install the banking trojan on victims’ devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.