Advisory
Published 2026-10-08
Verified 2026-10-09

Zscaler ThreatLabz: new Anatsa (TeaBot) banking-trojan installer on Google Play posed as a PDF reader with 10,000+ installs

On 8 October 2026 Zscaler ThreatLabz said it had found another new installer for the Anatsa (TeaBot) Android banking trojan distributed through the Google Play Store, disguised as a PDF reader with more than 10,000 installs, and published the Play Store listing and indicators (installer and payload hashes, command-and-control addresses) in its alert. Anatsa uses a dropper model: the harmless-looking app is installed first, then downloads the banking payload, often presented as an app update, and overlays fake login screens to steal banking credentials. The install figure is for the dropper app, not confirmed infections; the alert does not name targeted banks or countries, or say whether Google has removed the listing. Earlier ThreatLabz analysis documented Anatsa using environment checks and malformed APK archives to avoid analysis. Primary: Zscaler ThreatLabz (X); wire: Cyber Security News.

Product
Android PDF reader app on Google Play (Anatsa/TeaBot dropper)
Versions
n/a — malicious app
Exploited in Australia?
unknown
Patch to
Uninstall unfamiliar document/PDF reader apps that asked for Accessibility access; keep Google Play Protect on; banks and MDM teams should block the published hashes and C2 addresses.

Primary: Zscaler ThreatLabz on X — new Anatsa installer on Google Play disguised as a PDF reader (8 Oct 2026) · Vendor: Zscaler ThreatLabz — Technical analysis of Anatsa campaigns on Google Play (background) · Cyber Security News — Malicious PDF reader with 10,000+ installs on Google Play delivers Anatsa (9 Oct 2026)

tech network cloud