Is Google Play Still Safe? PDF App Found Stealing Banking Credentials
- 19/12/2025
A new wave of Android banking malware has resurfaced, once again exposing the growing risks hidden inside seemingly harmless mobile applications. Security researchers warn that a fake PDF reader and file management app has successfully bypassed Google Play’s security checks, silently delivering the notorious Anatsa (TeaBot) malware to unsuspecting users.
Disguised as a productivity tool, the malicious app targeted users looking for simple document-handling utilities—turning convenience into a costly mistake.
A Trusted-Looking App, A Hidden Threat
According to findings from Zscaler ThreatLabz, the application named “Document Reader – File Manager”, published by developer ISTOQMAH, accumulated over 50,000 downloads before being detected and removed.
At first glance, the app appeared legitimate:
-
Clean user interface
-
Convincing feature descriptions
-
Promises of efficient document handling
Behind the scenes, however, it quietly requested sensitive permissions and prepared the environment for malware deployment—opening the door to direct attacks on banking applications.
Anatsa Banking Malware: A Persistent Global Threat
First identified in 2020, Anatsa (also known as TeaBot) has evolved into one of the most dangerous Android banking malware families. Once active on a device, it can:
-
Steal banking credentials
-
Log keystrokes
-
Display fake login overlays
-
Perform fraudulent transactions automatically
Recent variants have expanded their reach to over 830 financial institutions worldwide, targeting not only traditional banks but also cryptocurrency platforms across regions such as Europe, Asia, and beyond.
Advanced Evasion Techniques to Bypass Detection
The latest campaign demonstrates how far mobile malware has evolved. To avoid analysis and detection, the attackers employed multiple stealth techniques, including:
-
DES encryption to conceal malicious strings
-
Device model checks to evade emulators used by analysts
-
Hidden payloads inside malformed ZIP files
-
Downloading malware as a fake “update” after installation
If suspicious conditions were detected, the app would behave like a normal file manager—effectively deceiving both users and automated security systems.
From Accessibility Abuse to Financial Theft
Once deployed, Anatsa attempts to abuse Android Accessibility Services, a feature designed to assist users with disabilities but frequently exploited by malware.
By gaining these privileges, the malware can:
-
Overlay fake banking login screens
-
Read SMS messages, including OTP codes
-
Fully control user interactions without detection
This allows attackers to steal credentials in real time and drain accounts before victims realize anything is wrong.
Security researchers have recently identified 77 similar malicious apps, totaling over 19 million downloads, all removed by Google after discovery—highlighting how utility apps remain a prime infection vector.
What Android Users and Organizations Should Do
Although no specific damage figures have been reported in Vietnam, this attack model poses a high risk due to widespread use of free utility apps. Security experts recommend:
-
Install apps only from reputable developers with strong reviews
-
Carefully review permission requests before granting access
-
Avoid in-app update prompts outside official app stores
-
Enable Google Play Protect and run regular scans
-
Use trusted mobile security solutions
-
If compromised: uninstall immediately, change banking passwords, and monitor transactions closely
DTG Insight
Official app stores are no longer a guaranteed safe zone. As malware grows more sophisticated, attackers increasingly exploit trust, convenience, and user habits rather than technical weaknesses alone.
Banking malware like Anatsa proves that a single careless installation can lead to financial loss, data exposure, and full device compromise. Continuous awareness and layered security are now essential—not optional.
DTG will continue monitoring emerging mobile threats and sharing timely intelligence to help organizations and users strengthen their digital defense posture.



