Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
Malware
/
Anatsa
Malware
Anatsa
Also known as:
ReBot · TeaBot · Toddler
Indicators of Compromise
2
Filename
Cleanova
Filename
PDF reader app
MITRE ATT&CK TTPs
3
T1059
Command and Scripting Interpreter
Execution
T1071
Application Layer Protocol
Command And Control
T1218
System Binary Proxy Execution
Defense Evasion
Source Articles
IT threat evolution in Q2 2026. Mobile statistics
In Q2 2026, mobile threats continued to evolve with a notable presence of banking Trojans, particularly variants of Mamont and Creduz. Attackers increasingly used malicious loaders distributed through Google Play, including trojanized apps like a PDF reader and the Cleanova app, to deliver banking malware such as Anatsa. These loaders employed sophisticated evasion techniques, including conditional payload delivery based on installation source telemetry, to bypass app store reviews and target specific users.
securelist
·
4d ago