Threat reportMalwareTL-2026-3099
Malicious PDF Reader on Google Play (10,000+ installs) Delivers Anatsa (TeaBot) Banking Trojan
Malicious PDF Reader on Google Play (10,000+ installs) (TL-2026-3099), also tracked as Anatsa, is a high-severity malware campaign, first published 2026-10-09. It has no confirmed attribution, affects Google Android (devices installing the malicious app from Google Play), maps to 15 MITRE ATT&CK techniques (T1406, T1407, T1417.001), and is covered by 9 detection rules and 27 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 27Indicators of compromise
Key facts for TL-2026-3099
- Threat ID
- TL-2026-3099
- Also known as
- Anatsa, TeaBot
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- finance, banking, cryptocurrency, consumer
- Target regions
- Europe, germany, united kingdom, spain, finland, south korea, singapore, united states of america
- Detection rules
- 9
- Indicators of compromise
- 27
Malware and tooling in Malicious PDF Reader on Google Play (10,000+ installs)
Malware and tooling: Anatsa, FakeUpdates
How Malicious PDF Reader on Google Play (10,000+ installs) works
A fraudulent PDF reader app on Google Play (package com.railforge.footplate.documentreader_pdfviewer) with 10,000+ installs acted as a dropper for the Anatsa (TeaBot) Android banking trojan. Zscaler ThreatLabz identified the installer on 2026-10-08; Google Play removal status was not confirmed in available reporting.
Zscaler ThreatLabz identified a malicious Android app disguised as a PDF/document reader on Google Play, package com.railforge.footplate.documentreader_pdfviewer, with more than 10,000 installs. The app is a two-stage dropper: the app installed first appears to function as a document reader and acts as a delivery tool for a separate malicious component, the Anatsa (aka TeaBot) banking trojan, which it fetches after passing store review and presents as an application update. Reported installer MD5 is 152d8649a03667dbf4b94312d185c41d and payload MD5 is 2451fae883ec7a4e7876d6abe486e1eb. The installer-side delivery endpoint is railforgefootplate.com/disclaimers.txt; the payload communicates with C2 servers at 193.24.123.18:85/api/ and 162.252.173.37:85/api/. Per the Cyber Security News write-up, the sample uses malformed APK archive headers, runtime code decryption and device environment checks to avoid researcher sandboxes; it requests SMS and accessibility permissions, contacts its control server and checks for targeted financial apps. The server then supplies fake login pages matching the apps found on the phone, and credentials typed into them are sent to the attackers rather than the bank.
This follows a recurring Anatsa distribution pattern documented by ThreatLabz. In the May 2024 report (90+ apps, ~5.5M installs, 650+ targeted institutions), decoy PDF/QR readers downloaded a remote DEX file loaded via reflection; the final DEX was hidden in asset files and decrypted with a static key; compression parameters in the manifest were deliberately corrupted; and fake login pages were delivered via JavaScript-interface-enabled webviews. In the August 2025 report, the DEX was concealed in a JSON file dropped at runtime and promptly deleted, the parent installer decrypted strings at runtime with a dynamically generated DES key, the APK ZIP obfuscator used corrupted headers and invalid compression/encryption flags, and a file-manager view was shown when emulator or device-model checks failed. Package names and installation hashes were periodically altered. C2 traffic is single-byte XOR encoded (key 66) over HTTP on port 85 with /api/ paths. Accessibility is abused to auto-enable SYSTEM_ALERT_WINDOW, READ_SMS, RECEIVE_SMS and USE_FULL_SCREEN_INTENT. The 2025 configuration exposed commands such as hide_sms, gauth_confirm, lock_device and extensive_logging, with injects_version 254 and keyloggers_version 403; keylogger functionality was present in that variant. Targeting grew to 831 financial institutions plus 150+ banking/crypto apps, adding Germany and South Korea.
The April 2026 campaign (com.groundstation.informationcontrol.filestation_browsefiles_readdocs, 10,000+ downloads per one report; a related Oct 2026 article cites >100,000 for an earlier outbreak) used an initial payload URL of 23.251.108.10:8080/privacy.txt and the same C2 IPs 193.24.123.18 and 162.252.173.37 plus 172.86.91.94, showing the October 2026 sample reuses established infrastructure. Sample-specific behaviors of the October 2026 installer beyond those in the source, and its targeted institution list, were not confirmed; items drawn from prior campaigns are noted as such. Severity is analyst-assigned; no CVE or CVSS applies. BeaconBeagle returned HTTP 404 for 193.24.123.18 and an empty result set for the railforgefootplate.com config search at research time. Zscaler detection names from prior reports: Android.Banker.Anatsa, AND/Agent5.AE, AndroidOS/Agent.BOI.
MITRE ATT&CK techniques used in TL-2026-3099
Defense Evasion
T1406 Obfuscated Files or Information; T1516 Input Injection; T1630.002 File Deletion; T1633.001 System Checks; T1655.001 Match Legitimate Name or Location
defense-evasion
T1407 Download New Code at Runtime
Credential Access
T1417.001 Keylogging; T1417.002 GUI Input Capture
Discovery
T1418 Software Discovery; T1426 System Information Discovery
Command and Control
T1437.001 Web Protocols; T1521 Encrypted Channel; T1544 Ingress Tool Transfer
Collection
Exfiltration
Affected products and versions in Malicious PDF Reader on Google Play (10,000+ installs)
- Google — Android (devices installing the malicious app from Google Play)
Vulnerable versions: Android devices with com.railforge.footplate.documentreader_pdfviewer installed
Remediation for Malicious PDF Reader on Google Play (10,000+ installs)
Immediate actions
- Uninstall com.railforge.footplate.documentreader_pdfviewer from any device where it is present and run a Google Play Protect scan
- Block railforgefootplate.com, 193.24.123.18, 162.252.173.37, 172.86.91.94 and 23.251.108.10 at DNS/proxy/firewall, and alert on outbound HTTP to port 85 /api/ paths
- If the app was installed, treat banking and crypto credentials as compromised: change passwords from a clean device and notify the bank
- Review accounts for unauthorized transactions and revoke accessibility grants
Workarounds
- Disable install of unknown-source apps and deny Accessibility Service access to non-assistive apps
- Keep Google Play Protect enabled
Longer-term hardening
- Enforce MDM policy restricting installs to vetted apps and flag apps requesting Accessibility Service plus SMS permissions
- Deploy mobile threat defense with runtime behavioral detection of dynamic DEX loading and update-install prompts from non-Play sources
- Educate users that PDF/QR/file reader utilities rarely need accessibility or SMS permissions
Timeline of Malicious PDF Reader on Google Play (10,000+ installs)
- Anatsa (TeaBot) Android banking trojan first appears in 2020 (year-level date; exact day not sourced).
- Zscaler ThreatLabz publishes technical analysis of Anatsa campaigns: 90+ malicious Google Play apps, ~5.5M installs, 650+ targeted financial institutions; PDF and QR reader decoys had 70,000+ installs.
- ThreatLabz reports updated Anatsa variant: DES runtime string decryption, DEX hidden in JSON and deleted, emulator checks, corrupted ZIP headers, 831+ targeted institutions and 150+ new banking/crypto apps, new Germany and South Korea coverage.
- The 2025 variant configuration exposes commands hide_sms, gauth_confirm, lock_device and extensive_logging, with injects_version 254 and keyloggers_version 403 (publication-adjacent date; reported in the 2025 analysis).
- Reporting on fake document reader com.groundstation.informationcontrol.filestation_browsefiles_readdocs (10,000+ downloads) distributing Anatsa via 23.251.108.10:8080/privacy.txt and C2s 172.86.91.94, 193.24.123.18, 162.252.173.37; Google removed the app.
- Secondary outlets (Punto Informatico, VNReview) report the recurring Anatsa Play Store campaign.
- Zscaler ThreatLabz identifies malicious PDF reader com.railforge.footplate.documentreader_pdfviewer (10,000+ installs) as an Anatsa installer on Google Play.
- Cyber Security News publishes IOCs for the PDF reader dropper and Anatsa payload; Google Play removal status unconfirmed. BeaconBeagle returns no records for the C2 IP/domain.
Sources cited for Malicious PDF Reader on Google Play (10,000+ installs)
- Malicious PDF Reader With 10,000+ Installs on Google Play Delivers Anatsa Banking Trojan
- Zscaler ThreatLabz - Technical Analysis of Anatsa Campaigns: Android Banking Malware Active on Google Play
- Zscaler ThreatLabz - Android Document Readers and Deception: Tracking the Latest Updates to Anatsa
- Fake Document Reader on Google Play Delivered Anatsa Android Banking Malware
- VPNCentral - Fake Document Reader on Google Play Delivered Anatsa Android Banking Malware
- Punto Informatico - Anatsa colpisce ancora, trojan bancario sul Play Store
- VNReview - Google Play lai xuat hien app doc file cai ma doc Anatsa
- BeaconBeagle config search for railforgefootplate.com (no matches)
Detection coverage for TL-2026-3099
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3099 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-3099
9 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.