# Malicious PDF Reader on Google Play (10,000+ installs) Delivers Anatsa (TeaBot) Banking Trojan

> A fraudulent PDF reader app on Google Play (package com.railforge.footplate.documentreader_pdfviewer) with 10,000+ installs acted as a dropper for the Anatsa (TeaBot) Android banking trojan. Zscaler ThreatLabz identified the installer on 2026-10-08; Google Play removal status was not confirmed in available reporting.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3099
- **ID:** TL-2026-3099
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 27 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Zscaler ThreatLabz identified a malicious Android app disguised as a PDF/document reader on Google Play, package com.railforge.footplate.documentreader_pdfviewer, with more than 10,000 installs. The app is a two-stage dropper: the app installed first appears to function as a document reader and acts as a delivery tool for a separate malicious component, the Anatsa (aka TeaBot) banking trojan, which it fetches after passing store review and presents as an application update. Reported installer MD5 is 152d8649a03667dbf4b94312d185c41d and payload MD5 is 2451fae883ec7a4e7876d6abe486e1eb. The installer-side delivery endpoint is railforgefootplate.com/disclaimers.txt; the payload communicates with C2 servers at 193.24.123.18:85/api/ and 162.252.173.37:85/api/. Per the Cyber Security News write-up, the sample uses malformed APK archive headers, runtime code decryption and device environment checks to avoid researcher sandboxes; it requests SMS and accessibility permissions, contacts its control server and checks for targeted financial apps. The server then supplies fake login pages matching the apps found on the phone, and credentials typed into them are sent to the attackers rather than the bank.

This follows a recurring Anatsa distribution pattern documented by ThreatLabz. In the May 2024 report (90+ apps, ~5.5M installs, 650+ targeted institutions), decoy PDF/QR readers downloaded a remote DEX file loaded via reflection; the final DEX was hidden in asset files and decrypted with a static key; compression parameters in the manifest were deliberately corrupted; and fake login pages were delivered via JavaScript-interface-enabled webviews. In the August 2025 report, the DEX was concealed in a JSON file dropped at runtime and promptly deleted, the parent installer decrypted strings at runtime with a dynamically generated DES key, the APK ZIP obfuscator used corrupted headers and invalid compression/encryption flags, and a file-manager view was shown when emulator or device-model checks failed. Package names and installation hashes were periodically altered. C2 traffic is single-byte XOR encoded (key 66) over HTTP on port 85 with /api/ paths. Accessibility is abused to auto-enable SYSTEM_ALERT_WINDOW, READ_SMS, RECEIVE_SMS and USE_FULL_SCREEN_INTENT. The 2025 configuration exposed commands such as hide_sms, gauth_confirm, lock_device and extensive_logging, with injects_version 254 and keyloggers_version 403; keylogger functionality was present in that variant. Targeting grew to 831 financial institutions plus 150+ banking/crypto apps, adding Germany and South Korea.

The April 2026 campaign (com.groundstation.informationcontrol.filestation_browsefiles_readdocs, 10,000+ downloads per one report; a related Oct 2026 article cites >100,000 for an earlier outbreak) used an initial payload URL of 23.251.108.10:8080/privacy.txt and the same C2 IPs 193.24.123.18 and 162.252.173.37 plus 172.86.91.94, showing the October 2026 sample reuses established infrastructure. Sample-specific behaviors of the October 2026 installer beyond those in the source, and its targeted institution list, were not confirmed; items drawn from prior campaigns are noted as such. Severity is analyst-assigned; no CVE or CVSS applies. BeaconBeagle returned HTTP 404 for 193.24.123.18 and an empty result set for the railforgefootplate.com config search at research time. Zscaler detection names from prior reports: Android.Banker.Anatsa, AND/Agent5.AE, AndroidOS/Agent.BOI.

## MITRE ATT&CK

- T1655.001 Match Legitimate Name or Location
- T1407 Download New Code at Runtime
- T1406 Obfuscated Files or Information
- T1633.001 System Checks
- T1630.002 File Deletion
- T1516 Input Injection
- T1544 Ingress Tool Transfer
- T1437.001 Web Protocols
- T1521 Encrypted Channel
- T1418 Software Discovery
- T1426 System Information Discovery
- T1417.002 GUI Input Capture
- T1417.001 Keylogging
- T1636.004 SMS Messages
- T1646 Exfiltration Over C2 Channel

## Sources

- [Malicious PDF Reader With 10,000+ Installs on Google Play Delivers Anatsa Banking Trojan](https://cybersecuritynews.com/malicious-pdf-reader/)
- [Zscaler ThreatLabz - Technical Analysis of Anatsa Campaigns: Android Banking Malware Active on Google Play](https://www.zscaler.com/blogs/security-research/technical-analysis-anatsa-campaigns-android-banking-malware-active-google)
- [Zscaler ThreatLabz - Android Document Readers and Deception: Tracking the Latest Updates to Anatsa](https://www.zscaler.com/jp/blogs/security-research/android-document-readers-and-deception-tracking-latest-updates-anatsa)
- [Fake Document Reader on Google Play Delivered Anatsa Android Banking Malware](https://cybersecuritynews.com/fake-document-reader-on-google-play/amp/)
- [VPNCentral - Fake Document Reader on Google Play Delivered Anatsa Android Banking Malware](https://vpncentral.com/?p=252582)
- [Punto Informatico - Anatsa colpisce ancora, trojan bancario sul Play Store](https://www.punto-informatico.it/anatsa-colpisce-ancora-trojan-bancario-play-store/)
- [VNReview - Google Play lai xuat hien app doc file cai ma doc Anatsa](https://www.vnreview.vn/threads/google-play-lai-xuat-hien-app-doc-file-cai-ma-doc-anatsa.75410/latest)
- [BeaconBeagle config search for railforgefootplate.com (no matches)](https://beaconbeagle.com/api/v1/configs/search?domain=railforgefootplate.com)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3099
