Although there are hundreds of thousands of applications in the Android application store Play Store that will make our work easier, malicious ones are not missing. Finally, applications that try to capture users’ banking data were detected.
Android applications that capture banking data!
According to software company ThreatFabric, the apps we’re talking about contain a Trojan horse called “Anatsa”. This virus; It targets 600 major finance applications in many countries, especially in the USA, England and Germany, and tries to seize the banking data of users.
According to the source, this virus is trying to steal the user’s identity, credit card, balance and payment information from the banking application and take control of the device and try to make some transactions. For example, sending money to another account on your behalf. Of course, since this process is done from the user’s device, it is not understood that it is a fraud. Until you notice, of course.
According to the software company, the apps containing the said Trojan are uploaded to the Play Store as if they were apps whose purpose is really to make things easier. Then when it is installed on the phone, it downloads software from outside. This software is also a virus, as you can imagine.
The names of Android apps that steal the user’s banking data and contain a trojan named Anatsa are as follows;
Application Name | Package Name |
---|---|
PDF Reader – Edit & View PDF | lsstudio.pdfreader.powerfultool.allinonepdf.goodpdftools |
PDF Reader & Editor | com.proderstarler.pdfsignature |
PDF Reader & Editor | moh.filemanagerrespdf |
All Document Reader & Editor | com.mikijaki.documents.pdfreader.xlsx.csv.ppt.docs |
All Document Reader and Viewer | com.muchlensoka.pdfcreator |
A Google spokesperson announced that the malicious apps we gave above have been removed from the Play Store and the developers have also been banned. Moreover, he stated that Google Play Protect automatically removes these applications from Android devices. However, there are users who say that it has not been removed.
So what do you guys think about this issue? You can share your views with us in the Comments section below.