Anatsa, also known as TeaBot, is an Android banking trojan identified by ThreatFabric in January 2021. It targets banking, investment, and cryptocurrency applications, combining credential theft with remote-access and semi-automated transfer capabilities to facilitate fraud directly on compromised devices. Its financial-application targets span multiple countries, including the Netherlands.
Anatsa abuses Android Accessibility Services to inspect screen content, log keystrokes and interface events, and interact with other applications. It downloads fraudulent login overlays that imitate targeted financial applications and transmits captured credentials to attackers. Additional capabilities include SMS interception, contact and device-information exfiltration, installed-application enumeration, and theft of Google Authenticator codes. Its remote-control functionality enables operators to observe the screen, launch applications, perform clicks and gestures, and manipulate text input. Anatsa can obstruct normal uninstallation and interfere with device shutdown or reboot, complicating removal.
Distribution campaigns use malicious dropper applications on Google Play disguised as functional PDF readers, document tools, QR scanners, and cryptocurrency utilities. These applications retrieve a separate banking payload, often presenting its installation as a required application update. Some droppers initially appear benign and acquire malicious functionality through later updates; device profiling and regional filtering can restrict payload delivery. Anatsa has also been distributed through parcel-themed smishing campaigns impersonating delivery services. Observed samples and delivery chains employ analysis-environment checks, runtime code encryption, and malformed application archives to hinder detection and analysis.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Anatsa was discovered by ThreatFabric in January 2021. Anatsa is a rather advanced Android banking trojan with RAT and semi-ATS capabilities.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
decrypts the malicious payload file called eepHM.json from the app’s assets folder to an executable dex format named ‘eepHM.odex’ and loads the decrypted file
These apps posed as QR code scanners, PDF scanners, and cryptocurrency apps.
This malware also terminates the predefined list of apps process(es)... that list includes a few popular security products... in order to remain undetected.
this malicious apk decrypts the malicious payload file called kbu.json from the app’s assets folder to an executable dex format named ‘kbu.odex’ and loads the decrypted file
the configuration contains filter rules based on device model. Based on the models being filtered out and the code of the dropper, we can draw a conclusion that this is done to avoid downloading the payload on emulators or research environment.
This is a classic Android bot, equipped with credential stealing capabilities such as the use of overlays (fake login screens) for crypto-currency wallet apps and Android banking apps.
Other features include keylogging, contact information and device information exfiltration, and accessibility logging.
the malware C2 sends the specific payload(s) to the victim device to perform an overlay attack and track all the activity related to the identified targeted application(s).
This is a classic Android bot, equipped with credential stealing capabilities such as the use of overlays (fake login screens) for crypto-currency wallet apps and Android banking apps.
Other features include keylogging, contact information and device information exfiltration, and accessibility logging.
The PTI team has de-anonymized the C&C server and discovered that Toddler has already infected more than 7,632 devices at the time of this report.
it's also designed to retrieve a malicious APK file hosted on GitHub
43 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
34 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan delivered through a malicious PDF reader using a separate installer and payload. Earlier research documented SMS and accessibility permission requests, detection of installed financial apps, and fake banking login pages that steal credentials. Historical samples also used environment checks, malformed APK headers, and encrypted runtime-loaded code; these techniques are not confirmed for the newly reported samples. The October 8, 2026 alert identifies separate installer and payload hashes and command-and-control endpoints. The reader's 10,000-plus installs do not establish the number of successful infections. Affected banks, victim countries, losses, and the current listing's removal status remain unconfirmed.
An Android trojan cited as an example of accessibility-service abuse and deceptive app distribution. The article reports that it reached Google Play disguised as a PDF viewer update in July 2025; that date is not identified as its discovery date.
Android banking trojan that targets financial applications to steal cryptocurrency assets and money.
Android banking trojan delivered via malicious Google Play loader apps using fake update prompts; once installed, it seeks information that can help criminals access financial accounts or approve fraudulent activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.