Threat reportMalwareTL-2026-3099

Malicious PDF Reader on Google Play (10,000+ installs) Delivers Anatsa (TeaBot) Banking Trojan

highACTIVE

Malicious PDF Reader on Google Play (10,000+ installs) (TL-2026-3099), also tracked as Anatsa, is a high-severity malware campaign, first published 2026-10-09. It has no confirmed attribution, affects Google Android (devices installing the malicious app from Google Play), maps to 15 MITRE ATT&CK techniques (T1406, T1407, T1417.001), and is covered by 9 detection rules and 27 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
15MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
27Indicators of compromise

Key facts for TL-2026-3099

Threat ID
TL-2026-3099
Also known as
Anatsa, TeaBot
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
finance, banking, cryptocurrency, consumer
Target regions
Europe, germany, united kingdom, spain, finland, south korea, singapore, united states of america
Detection rules
9
Indicators of compromise
27

Malware and tooling in Malicious PDF Reader on Google Play (10,000+ installs)

Malware and tooling: Anatsa, FakeUpdates

How Malicious PDF Reader on Google Play (10,000+ installs) works

A fraudulent PDF reader app on Google Play (package com.railforge.footplate.documentreader_pdfviewer) with 10,000+ installs acted as a dropper for the Anatsa (TeaBot) Android banking trojan. Zscaler ThreatLabz identified the installer on 2026-10-08; Google Play removal status was not confirmed in available reporting.

Zscaler ThreatLabz identified a malicious Android app disguised as a PDF/document reader on Google Play, package com.railforge.footplate.documentreader_pdfviewer, with more than 10,000 installs. The app is a two-stage dropper: the app installed first appears to function as a document reader and acts as a delivery tool for a separate malicious component, the Anatsa (aka TeaBot) banking trojan, which it fetches after passing store review and presents as an application update. Reported installer MD5 is 152d8649a03667dbf4b94312d185c41d and payload MD5 is 2451fae883ec7a4e7876d6abe486e1eb. The installer-side delivery endpoint is railforgefootplate.com/disclaimers.txt; the payload communicates with C2 servers at 193.24.123.18:85/api/ and 162.252.173.37:85/api/. Per the Cyber Security News write-up, the sample uses malformed APK archive headers, runtime code decryption and device environment checks to avoid researcher sandboxes; it requests SMS and accessibility permissions, contacts its control server and checks for targeted financial apps. The server then supplies fake login pages matching the apps found on the phone, and credentials typed into them are sent to the attackers rather than the bank.

This follows a recurring Anatsa distribution pattern documented by ThreatLabz. In the May 2024 report (90+ apps, ~5.5M installs, 650+ targeted institutions), decoy PDF/QR readers downloaded a remote DEX file loaded via reflection; the final DEX was hidden in asset files and decrypted with a static key; compression parameters in the manifest were deliberately corrupted; and fake login pages were delivered via JavaScript-interface-enabled webviews. In the August 2025 report, the DEX was concealed in a JSON file dropped at runtime and promptly deleted, the parent installer decrypted strings at runtime with a dynamically generated DES key, the APK ZIP obfuscator used corrupted headers and invalid compression/encryption flags, and a file-manager view was shown when emulator or device-model checks failed. Package names and installation hashes were periodically altered. C2 traffic is single-byte XOR encoded (key 66) over HTTP on port 85 with /api/ paths. Accessibility is abused to auto-enable SYSTEM_ALERT_WINDOW, READ_SMS, RECEIVE_SMS and USE_FULL_SCREEN_INTENT. The 2025 configuration exposed commands such as hide_sms, gauth_confirm, lock_device and extensive_logging, with injects_version 254 and keyloggers_version 403; keylogger functionality was present in that variant. Targeting grew to 831 financial institutions plus 150+ banking/crypto apps, adding Germany and South Korea.

The April 2026 campaign (com.groundstation.informationcontrol.filestation_browsefiles_readdocs, 10,000+ downloads per one report; a related Oct 2026 article cites >100,000 for an earlier outbreak) used an initial payload URL of 23.251.108.10:8080/privacy.txt and the same C2 IPs 193.24.123.18 and 162.252.173.37 plus 172.86.91.94, showing the October 2026 sample reuses established infrastructure. Sample-specific behaviors of the October 2026 installer beyond those in the source, and its targeted institution list, were not confirmed; items drawn from prior campaigns are noted as such. Severity is analyst-assigned; no CVE or CVSS applies. BeaconBeagle returned HTTP 404 for 193.24.123.18 and an empty result set for the railforgefootplate.com config search at research time. Zscaler detection names from prior reports: Android.Banker.Anatsa, AND/Agent5.AE, AndroidOS/Agent.BOI.

MITRE ATT&CK techniques used in TL-2026-3099

Defense Evasion

T1406 Obfuscated Files or Information; T1516 Input Injection; T1630.002 File Deletion; T1633.001 System Checks; T1655.001 Match Legitimate Name or Location

defense-evasion

T1407 Download New Code at Runtime

Credential Access

T1417.001 Keylogging; T1417.002 GUI Input Capture

Discovery

T1418 Software Discovery; T1426 System Information Discovery

Command and Control

T1437.001 Web Protocols; T1521 Encrypted Channel; T1544 Ingress Tool Transfer

Collection

T1636.004 SMS Messages

Exfiltration

T1646 Exfiltration Over C2 Channel

Affected products and versions in Malicious PDF Reader on Google Play (10,000+ installs)

  • Google — Android (devices installing the malicious app from Google Play)
    Vulnerable versions: Android devices with com.railforge.footplate.documentreader_pdfviewer installed

Remediation for Malicious PDF Reader on Google Play (10,000+ installs)

Immediate actions

  • Uninstall com.railforge.footplate.documentreader_pdfviewer from any device where it is present and run a Google Play Protect scan
  • Block railforgefootplate.com, 193.24.123.18, 162.252.173.37, 172.86.91.94 and 23.251.108.10 at DNS/proxy/firewall, and alert on outbound HTTP to port 85 /api/ paths
  • If the app was installed, treat banking and crypto credentials as compromised: change passwords from a clean device and notify the bank
  • Review accounts for unauthorized transactions and revoke accessibility grants

Workarounds

  • Disable install of unknown-source apps and deny Accessibility Service access to non-assistive apps
  • Keep Google Play Protect enabled

Longer-term hardening

  • Enforce MDM policy restricting installs to vetted apps and flag apps requesting Accessibility Service plus SMS permissions
  • Deploy mobile threat defense with runtime behavioral detection of dynamic DEX loading and update-install prompts from non-Play sources
  • Educate users that PDF/QR/file reader utilities rarely need accessibility or SMS permissions

Timeline of Malicious PDF Reader on Google Play (10,000+ installs)

  • Anatsa (TeaBot) Android banking trojan first appears in 2020 (year-level date; exact day not sourced).
  • Zscaler ThreatLabz publishes technical analysis of Anatsa campaigns: 90+ malicious Google Play apps, ~5.5M installs, 650+ targeted financial institutions; PDF and QR reader decoys had 70,000+ installs.
  • ThreatLabz reports updated Anatsa variant: DES runtime string decryption, DEX hidden in JSON and deleted, emulator checks, corrupted ZIP headers, 831+ targeted institutions and 150+ new banking/crypto apps, new Germany and South Korea coverage.
  • The 2025 variant configuration exposes commands hide_sms, gauth_confirm, lock_device and extensive_logging, with injects_version 254 and keyloggers_version 403 (publication-adjacent date; reported in the 2025 analysis).
  • Reporting on fake document reader com.groundstation.informationcontrol.filestation_browsefiles_readdocs (10,000+ downloads) distributing Anatsa via 23.251.108.10:8080/privacy.txt and C2s 172.86.91.94, 193.24.123.18, 162.252.173.37; Google removed the app.
  • Secondary outlets (Punto Informatico, VNReview) report the recurring Anatsa Play Store campaign.
  • Zscaler ThreatLabz identifies malicious PDF reader com.railforge.footplate.documentreader_pdfviewer (10,000+ installs) as an Anatsa installer on Google Play.
  • Cyber Security News publishes IOCs for the PDF reader dropper and Anatsa payload; Google Play removal status unconfirmed. BeaconBeagle returns no records for the C2 IP/domain.

Sources cited for Malicious PDF Reader on Google Play (10,000+ installs)

Detection coverage for TL-2026-3099

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3099 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
27 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-3099

9 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats