{"id":26508,"date":"2024-02-20T03:52:29","date_gmt":"2024-02-20T00:52:29","guid":{"rendered":"https:\/\/wikidollar.net\/26508\/delete-these-five-scary-android\/"},"modified":"2024-02-20T03:52:30","modified_gmt":"2024-02-20T00:52:30","slug":"delete-these-five-scary-android","status":"publish","type":"post","link":"https:\/\/wikidollar.net\/?p=26508","title":{"rendered":"Delete these five scary Android apps to avoid devastating personal implications"},"content":{"rendered":"<p>Delete these five scary Android apps to avoid devastating personal implications\u060c<\/p>\n<div>\n<p>Five malicious apps that racked up tens of thousands of downloads have been removed by Google Play after a research firm published a report on them.<\/p>\n<p>The apps contained the Anatsa banking Trojan and were searched by users in the United Kingdom, Czech Republic, Germany, Slovakia, Slovenia and Spain.  Initially, the apps specifically targeted <a class=\"wpil_keyword_link\" href=\"https:\/\/wikidollar.net\/tag\/galaxy\/\"   title=\"Samsung\" data-wpil-keyword-link=\"linked\">Samsung<\/a> users, but later they became manufacturer-independent.<\/p>\n<div>Research company <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.threatfabric.com\/blogs\/anatsa-trojan-returns-targeting-europe-and-expanding-its-reach\" class=\"external\">Threat Cloth<\/a> who was the first to report the resurgence of Anatsa revealed to <span style=\"font-style: italic;\"><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/anatsa-android-malware-downloaded-150-000-times-via-google-play\/\" class=\"external\">Computer beeping<\/a><\/span>    the names of fake applications.  They are as follows: <\/div>\n<div>\n<ol>\n<li>Phone Cleaner \u2013 File Explorer <\/li>\n<li>PDF Viewer &#8211; File Explorer<\/li>\n<li>PDF Reader &#8211; Viewer and Editor <\/li>\n<li>Phone Cleaner: File Explorer <\/li>\n<li>PDF reader: file manager <\/li>\n<\/ol>\n<\/div>\n<p>The fake apps were disguised as PDFs and cleaner apps and were designed in a way to achieve top new free rankings, thereby increasing their chances of being downloaded by unsuspecting users.<\/p>\n<div>It is estimated that the apps were downloaded between 150,000 and 200,000 times before being removed from the Play Store.  They used a multi-step process to infect devices without user interaction and evade detection.  They also used other sophisticated tactics, including abusing the accessibility service and bypassing restricted Android 13 settings.<\/div>\n<p>The Anatsa Trojan has Device Takeover (DTO) capabilities, which means it can take control of an infected device and perform actions on your behalf.  It can steal sensitive information from your phone and initiate transactions itself.<\/p>\n<p>As mentioned earlier, malicious apps are no longer available on <a class=\"wpil_keyword_link\" href=\"https:\/\/wikidollar.net\/tag\/google\/\"   title=\"Google\" data-wpil-keyword-link=\"linked\">Google<\/a> Play, but if you already have them on your phone, you will have to remove them yourself.<\/p>\n<p>To avoid falling prey to such apps in the future, do a thorough check before downloading an <a class=\"wpil_keyword_link\" href=\"https:\/\/wikidollar.net\/tag\/app\/\"   title=\"app\" data-wpil-keyword-link=\"linked\">app<\/a> by ensuring that it is from a trusted developer.  Another thing to look for is requested permissions, especially those related to the accessibility service.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Delete these five scary Android apps to avoid devastating personal implications\u060c Five malicious apps that racked up tens of thousands of downloads have been removed by Google Play after a research firm published a report on them. The apps contained the Anatsa banking Trojan and were searched by users in the United Kingdom, Czech Republic, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":26509,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[396,106,3283,5497,10916,10917,3488,1538],"class_list":["post-26508","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology","tag-android","tag-apps","tag-avoid","tag-delete","tag-devastating","tag-implications","tag-personal","tag-scary"],"blocksy_meta":[],"_links":{"self":[{"href":"https:\/\/wikidollar.net\/index.php?rest_route=\/wp\/v2\/posts\/26508","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wikidollar.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wikidollar.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wikidollar.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wikidollar.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=26508"}],"version-history":[{"count":1,"href":"https:\/\/wikidollar.net\/index.php?rest_route=\/wp\/v2\/posts\/26508\/revisions"}],"predecessor-version":[{"id":26510,"href":"https:\/\/wikidollar.net\/index.php?rest_route=\/wp\/v2\/posts\/26508\/revisions\/26510"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wikidollar.net\/index.php?rest_route=\/wp\/v2\/media\/26509"}],"wp:attachment":[{"href":"https:\/\/wikidollar.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=26508"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wikidollar.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=26508"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wikidollar.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=26508"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}