Delete these five scary Android apps to avoid devastating personal implications

Five malicious apps that have racked up tens of thousands of downloads have been removed by Google Play after a research firm published a report on them.

The apps contained the Anatsa banking trojan and tracked users in the UK, the Czech Republic, Germany, Slovakia, Slovenia and Spain. Initially, the applications were specifically aimed at Samsung users, but later became independent of the manufacturer.

Research firm ThreatFabric, which first reported the resurgence of Anatsa, revealed A flashy computer names of fake applications. They are as follows:
  1. Phone Cleaner – File Explorer
  2. PDF viewer – File Explorer
  3. PDF reader – viewer and editor
  4. Phone Cleaner: File Explorer
  5. PDF Reader: File Manager

The fake apps were disguised as PDFs and cleaner apps and were designed to make it to the top new freebies, increasing their chances of being downloaded by unsuspecting users.

The apps are believed to have been downloaded between 150,000 and 200,000 times before they were removed from the Play Store. They used a multi-stage process to infect devices without user interaction and avoid detection. They also used other sophisticated tactics, including abusing the accessibility service and bypassing Android 13’s limited settings.

The Anatsa Trojan has device takeover capabilities (DTO), which means it can take over an infected device and perform actions on your behalf. It can steal sensitive data from your phone and initiate transactions on its own.

As mentioned above, malicious apps are no longer available on Google Play, but if you already have them on your phone, you will need to delete them yourself.

To avoid becoming a victim of such apps in the future, before downloading any app, thoroughly check that it comes from a developer you trust. Another thing to pay attention to is the permissions requested, especially those related to the accessibility service.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *