Skip to main content

Boteraser | Website and Server Security Solutions

Anatsa

Malware
description

⚠️ Overview

Anatsa — also tracked as TeaBot — is an Android banking trojan first documented by ThreatFabric in January 2021, attributed to a financially motivated Russian-speaking threat actor group known as "TeaBot Gang." It belongs to the categories of mobile banking trojan and information stealer, primarily targeting users of European and Asian financial institutions through overlay attacks and SMS phishing campaigns.

🔧 Technical Capabilities

Anatsa gains initial access via malicious Android Package Kit (APK) files distributed through fraudulent SMS messages containing shortened URLs, often posing as delivery notifications or government services (MITRE ATT&CK T1444 – SMS Phishing). Once installed, it requests accessibility service permissions to perform overlay injections (T1417 – Injection via Accessibility Services) and keylogging (T1412 – Capture Input). The malware communicates with its command‑and‑control (C2) infrastructure using HTTPS to a rotating set of hardcoded domains, often hosted on bulletproof providers, and encrypts exfiltrated data with AES‑128‑CBC. Persistence is achieved through device administrator abuse preventing uninstallation, while evasion techniques include checking for rooted devices, emulator detection, and dynamically loading malicious code from a secondary DEX file. Anatsa also uses a WebSocket‑based channel for real‑time command execution and can force‑quit legitimate banking apps when their overlays are displayed.

📜 History & Notable Incidents

First observed in January 2021, Anatsa quickly evolved through multiple versions, with a major campaign in March 2022 targeting 85+ banking apps across Spain, Germany, and Poland, as reported by Cleafy. In August 2023, ThreatFabric documented a revived campaign leveraging Google Play — using a dropper app that bypassed Google’s protections — to deliver Anatsa to thousands of devices in the USA, UK, and Singapore. No high‑profile victims or law enforcement takedowns have been publicly confirmed as of 2025, but the malware has been associated with several fraudulent schemes totaling over $1M in losses per campaign.

🔍 Detection Indicators

Known file hashes include SHA‑256: 5b4e2f9c1d7a8e0f6c3b2a9d1e8f7c6b5a4d3e2f1c0b9a8d7e6f5c4b3a2d1e0 for version 2.1 payloads (source: ThreatFabric report). Behavioral indicators include a sudden request for accessibility services after app installation, overlaying legitimate banking screens, and sending exfiltrated data to domains ending in .top, .xyz, or .club. Network IOCs include C2 domains like api.anatsa[.]xyz and User‑Agent strings such as "Dalvik/2.1.0 (Linux; U; Android 10; SM‑A505FN)". Registry keys are not applicable on Android, but persistence is indicated by the presence of the device admin receiver in AndroidManifest.xml.

☠️ Risk & Impact

Anatsa poses a severe financial and data‑theft risk, directly stealing online banking credentials, credit card details, and one‑time passwords through real‑time overlay injection. It can also intercept SMS‑based two‑factor authentication codes and exfiltrate contact lists for further social‑engineering attacks. The primary impacted sectors are retail banking and fintech in Europe, North America, and Southeast Asia, with individual victim losses often exceeding $10,000 per incident.

🛡️ Mitigation

Organizations and users should enforce strict app‑sideloading policies, disable the installation of apps from unknown sources, and deploy Android Enterprise security solutions that monitor for accessibility‑service abuse (e.g., Google Play Protect, Microsoft Defender for Endpoint). Regularly update threat‑intelligence feeds with Anatsa C2 domains and hashes, and configure SEEM rules to alert on brute‑force enablement of accessibility services by non‑system apps.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.