Thousands of people have downloaded this data-stealing Android app

David Artykov
Purple Team
Published in
2 min readMar 4, 2022

--

Retrieved from pplware.sapo.pt

In an effort to seize identities and two-factor authentication tokens, cybercriminals have effectively hidden a banking Trojan on the Google Play Store, potentially compromising thousands of devices. The TeaBot banking trojan, also known as Anatsa or Toddler, was discovered as a second-stage payload from a potentially valid app, according to a recent analysis from security

--

--