Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google Play — Threadlinqs Intelligence
As of 2026-07-02, Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google Play is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 33 indicators of compromise.
Threat ID: TL-2026-1059 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
A dropper app named "File Horizon Explorer" (com.westhorizont.appsforge.filehorizon_explorereaddocuments), disguised as a document reader/file manager, was distributed on Google Play and delivered the
Anatsa (also tracked as TeaBot) is a mature Android banking trojan family, active since 2020, that Zscaler ThreatLabz has repeatedly observed being distributed through Google Play Store dropper applications masquerading as document readers, file managers, PDF viewers, and QR code scanners. In the campaign covered by this report, the dropper package com.westhorizont.appsforge.filehorizon_explorereaddocuments ("File Horizon Explorer") functioned as a fully working file-reading utility to pass Google Play review and satisfy sandboxed dynamic analysis, while covertly staging the Anatsa payload.
The infection chain follows Anatsa's established three-stage model: a benign-looking Stage 1 dropper (published under a legitimate-sounding developer identity to build trust and downloads) fetches a Stage 2 configuration/DEX component from attacker infrastructure once environmental checks (emulator detection, device-model verification, VM/sandbox fingerprinting) pass; a Stage 3 payload is then installed, in more recent campaign iterations directly as an APK update rather than via reflective DEX loading, streamlining infection and reducing detection surface. The payload is concealed using a corrupted ZIP archive technique — invalid/forged compression and encryption flags in the manifest that standard Java/Android ZIP parsers tolerate but which break common static-analysis and antivirus ZIP header validators. Internal strings, including C2 endpoints and configuration values, are protected with runtime DES decryption using dynamically generated keys, and C2 session traffic is further obscured with a single-byte XOR cipher (observed key value: decimal 66).
Once installed, Anatsa requests Accessibility Service permissions and abuses the granted API surface to silently self-grant additional dangerous permissions (SYSTEM_ALERT_WINDOW, READ_SMS, RECEIVE_SMS, USE_FULL_SCREEN_INTENT) without further user interaction. The trojan fingerprints installed applications on the device, and when a targeted banking, financial-services, or cryptocurrency-exchange app is detected, it downloads a tailored HTML/JavaScript injection page from C2 and renders it as a full-screen WebView overlay (using a JavaScript Interface / JSI bridge) on top of the legitimate app to phish credentials. A built-in keylogger driven by the Accessibility API records all on-device keystrokes, and SMS read/receive permissions let the malware intercept OTP/2FA codes and exfiltrate or suppress banking SMS notifications, enabling full account-takeover and transaction fraud even against institutions using SMS-based two-factor authentication.
The campaign this report covers targets over 831 financial institutions globally — an increase from the ~650 institutions targeted in earlier 2025 Anatsa waves — with expanded coverage of Germany and South Korea alongside established targeting of the US, UK, and broader Europe, plus more than 150 newly added banking and cryptocurrency applications. Operators rotate dropper package names, developer identities, and installer file hashes frequently to evade Play Store fraud detection and AV signature matching; related droppers in the same cluster (fileqrutility, tmzcwkcjd, filemanagerwithpdfsupport, fileedge_organizerviewer, docxploremanagerviewer, and others) collectively exceeded 90 apps and 5.5-19 million installs across successive waves tracked by Zscaler ThreatLabz.
Weaknesses (CWE)
CWE-506, CWE-451, CWE-311, CWE-522
Target sectors: finance, banking, cryptocurrency
Target regions: united states of america, united kingdom, germany, spain, finland, south korea, singapore, Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 33 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
5 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1476, T1475, T1624, T1541, T1624, T1626, T1655, T1406, T1406, T1523