Anatsa Android malware downloaded 150,000 times via Google Play (www.bleepingcomputer.com)
from IllNess@infosec.pub to securitynews@infosec.pub on 20 Feb 2024 01:57
https://infosec.pub/post/8625712

The five malicious apps are:

  1. Phone Cleaner - File Explorer (com.volabs.androidcleaner)
  2. PDF Viewer - File Explorer (com.xolab.fileexplorer)
  3. PDF Reader - Viewer & Editor (com.jumbodub.fileexplorerpdfviewer)
  4. Phone Cleaner: File Explorer (com.appiclouds.phonecleaner)
  5. PDF Reader: File Manager (com.tragisoap.fileandpdfmanager)

#securitynews

threaded - newest

xia@links.hackliberty.org on 20 Feb 2024 02:10 collapse

But… but… muh play protect! :)

IllNess@infosec.pub on 20 Feb 2024 02:32 collapse

Here’s the worst part:

At the time of writing, Google removed all Anatsa dropper apps from the official Android store except for the PDF Reader, which continues to be available.

I no longer see the app. At least Google is doing something.