In case you missed it: Bank info-stealing malware found in 90+ Android apps with 5.5M installs

The apps identified have since been removed from Google Play, but make sure you didn't install one.
 By 
Cecily Mauran
 on 
unauthorized credit card alert on an android screen
The malware was disguised as PDF and QR code readers. Credit: Thai Liang Lim / iStock / Getty Images Plus / Getty Images

A report from cybersecurity firm Zscaler has discovered over 90 malicious Android apps uploaded to Google Play over the past few months, including a particularly sophisticated trojan called Anatsa.

Collectively, the malware apps have been installed over 5.5 million times.

How Anatsa malware tries to fool Android users

As of Thursday, Google has banned the apps identified in the report, according to BleepingComputer. Anatsa, also known as "TeaBot," and other malware in the report, are dropper apps that masquerade as PDF and QR code readers, photography, and health and fitness apps. As the outlet reported, the findings demonstrate the "high risk of malicious dropper apps slipping through the cracks in Google's review process."


You May Also Like

Although Anatsa only accounts for around two percent of the most popular malware, it does a lot of damage. It's known for targeting over 650 financial institutions — and two of its PDF and QR code readers had both amassed over 70,000 downloads at the time the report was published.

Once installed as a seemingly legitimate app, Anatsa uses advanced techniques to avoid detection and gain access to banking information. The two apps mentioned in the report were called "PDF Reader and File Manager" by Tsarka Watchfaces and "QR Reader and File Manager" by risovanul. So, they definitely have an innocuous look to unsuspecting Android users.

The majority of apps containing the malware were classified as tools like file managers, editors, and translators. Other categories of apps included photography, productivity, and "personalization," which was unspecified, but might include apps for customizing Android home screens and wallpaper.

These malware-infected apps may have been taken down, but it's an uneasy reminder to remain vigilant about which apps you're installing.

Mashable Image
Cecily Mauran
Tech Reporter

Cecily is a tech reporter at Mashable who covers AI, Apple, and emerging tech trends. Before getting her master's degree at Columbia Journalism School, she spent several years working with startups and social impact businesses for Unreasonable Group and B Lab. Before that, she co-founded a startup consulting business for emerging entrepreneurial hubs in South America, Europe, and Asia. You can find her on X at @cecily_mauran.

Mashable Potato

Recommended For You
How AdultFriendFinder subscriptions appear on your bank statement
By Jack Dawes
AFF logo appearing through microscope on phone

Everything you need to know about the malware stealing data from Mac users
MacBook in the dark using Terminal

Stay juiced up anywhere with 25% off the Anker Prime Power Bank
Anker Prime Power Bank on green and lime green abstract background

How hackers are stealing millions from ATMs, FBI warns
a card being inserted into an atm

Do you have one of these 17 browser extensions? They could be tracking your browsing history.
safari and chrome apps on phone

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

Google launches Gemma 4, a new open-source model: How to try it
Google Gemma


What's new to streaming this week? (April 3, 2026)
A composite of images from film and TV streaming this week.
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!