TeaBot (also tracked as Anatsa) infected Android devices through smishing campaigns and trojanized apps, including fake media, delivery, and utility software such as VLC, DHL, UPS, TeaTV, and QR-code scanners. Researchers found the malware later reached users through Google Play droppers that displayed fake update prompts and fetched second-stage APKs from GitHub, extending distribution beyond SMS lures. Campaigns initially focused on European banks, especially in Spain, Germany, and Italy, before expanding to roughly 400 targeted applications spanning banking, cryptocurrency, wallet, insurance, and other financial services in additional regions including the United States, Russia, and Hong Kong.
Once installed, TeaBot abused Android Accessibility Services to gain broad control of the device, then hid its icon, intercepted SMS messages, logged keystrokes, captured screens, enumerated installed apps, and launched overlay attacks to steal credentials and 2FA codes from targeted apps. Analysts said the malware dynamically decrypted and loaded additional payloads, used partially XOR-encrypted command-and-control traffic, and in some cases terminated selected processes, including security tools, to reduce detection. Reports tied some second-stage payload delivery to GitHub repositories and noted that malicious Play Store apps had accumulated significant downloads before being identified and removed.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
14 events from the most recent confirmed update back to the earliest known activity.
GBHackers, citing Cleafy, said TeaBot resurfaced after a period of reduced visibility until February 21, 2022.
Cleafy linked the second-stage 'QR Code Scanner: Add-on' app to two GitHub repositories owned by feleanicusor that contained multiple TeaBot samples dated February 17, 2022.
Bitdefender correlated telemetry and GitHub history showing that the Google Play app 'QR Code Reader - Scanner App' distributed 17 different TeaBot variants between December 6 and January 17.
ThreatFabric previously reported six Anatsa droppers on Google Play since June 2021, showing sustained abuse of the official app store for TeaBot distribution.
Bitdefender said additional Google Play apps including QR Scanner APK, QR Code Scan, and Smart Cleaner had been distributing TeaBot since at least April 2021.
Samples observed in March 2021 showed TeaBot broadening its targeting from Spanish banks to include German and Italian banks, while supporting six European languages.
Multiple references state TeaBot was first noticed or observed at the beginning of 2021 as an Android banking trojan initially spread through smishing campaigns.
Cleafy reported that TeaBot initially focused on Spanish banks in January 2021, marking the early observed targeting scope of the Android banking trojan.
PRODAFT reported that mobile banking malware attacks involving Toddler/TeaBot were rising across European countries in the second half of 2020, with Spain, Germany, Switzerland, and the Netherlands identified as primary targets. The report also said Toddler mainly targeted Spain at the time of analysis and had infected more than 7,632 devices after PRODAFT de-anonymized its command-and-control server.
K7 analyzed a fake QR Code & BarCode Scanner app on Google Play that prompted users to install an 'update' and downloaded the TeaBot payload main.apk from a GitHub repository operated by mattiebryan4570.
K7 documented a TeaBot sample masquerading as VLC Media Player, detailing its abuse of Accessibility Services, SMS interception, keylogging, overlay delivery, and C2 endpoints 185.215.113.31:80/api/ and 178.32.130.170:80/api/.
Researchers reported TeaBot's target list growing to roughly 400 applications, including banking, cryptocurrency, wallet, and digital insurance apps in regions such as the United States, Russia, and Hong Kong.
Cleafy researchers identified a malicious QR code and barcode scanner app on Google Play, published as 'QR BarCode Scanner Bussiness LLC,' that used a fake update flow to sideload TeaBot.
Researchers reported TeaBot being distributed through trojanized Google Play apps such as 'QR Code Reader - Scanner App' that fetched GitHub-hosted payloads and used fake update prompts to sideload the malware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
labs.k7computing.com
Open sourcegbhackers.com
Open sourcethehackernews.com
Open sourcelabs.k7computing.com
Open sourcecleafy.com
Open sourcebitdefender.com
Open sourceprodaft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.