Google Play Store Apps That Stole Bank Credentials Were Downloaded 300,000 Times: Report

The Android apps posed as QR Scanners, PDF Scanners, or cryptocurrency wallets.

Advertisement
By Siddhant Chandra | Updated: 30 November 2021 13:16 IST
Highlights
  • Crooks initiated banking malware installations to target specific regions
  • Malicious apps had users download updates from third-party sources
  • Google Play store restrictions were bypassed by reducing apps’ footprint

Malware from the Anatsa family were responsible for the most infections

Photo Credit: Google

Malicious Android apps that stole sensitive financial data were downloaded over 300,000 times from the Google Play store, according to a report published by researchers at ThreatFabric. They discovered that users had their banking details stolen by seemingly benign-looking apps. User passwords, two-factor authentication codes, logged keystrokes, and more were siphoned via apps that posed as QR scanners, PDF scanners, or cryptocurrency wallets. These apps are primarily part of four malware families — Anatsa, Alien, Hydra, and Ermac. Google has tried to tackle the problem by introducing several restrictions to seize the distribution of fraudulent apps. This has motivated these cybercriminals to develop ingenious means to bypass the Google Play store restrictions.

In its post, ThreatFabric explained that such applications only introduce the malware content through third-party sources after being downloaded from the Google Play store. These applications reportedly entice users by offering additional content through such third-party updates. In some cases, the malware operators are said to have manually triggered malicious updates after tracking the geographical location of the infected devices.

The malicious Android apps on the Google Play store spotted by the researchers included QR Scanner, QR Scanner 2021, PDF Document Scanner, PDF Document Scanner Free, Two Factor Authenticator, Protection Guard, QR CreatorScanner, Master Scanner Live, CryptoTracker, and Gym and Fitness Trainer.

Advertisement

The biggest perpetrator of such activities has been the Anatsa malware family as per the report, which was downloaded over 100,000 times. Such applications appeared to be legitimate as they had a large number of positive reviews and offered the depicted functionality upon use. However, after the initial download from Google Play, these apps made users install third-party updates to continue using them. The malware installed was then reportedly able to steal banking details and even capture everything shown on the device's screen.

Advertisement

Google published a blog post in April marking out the steps they have taken to deal with such nefarious apps. This included reducing the developer access to sensitive permissions. However, as per a test conducted by German IT security institute AV-Test in July, Google Play Protect failed to provide a competent level of security compared to other prominent anti-malware programs. It was only able to detect around two-thirds of the 20,000 malicious apps that were tested.

The ingenuity of such malware operators has reduced the reliability of automatic malware detectors, the ThreatFabric claims. Users will have to be vigilant regarding the access they grant to applications and the sources they download the apps and their updates from.


What can you expect from Black Friday and Cyber Monday 2021? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Lava Agni 4 Price Range, Features Leaked; Will Launch in These Colourways
  2. Apple's Low-Cost MacBook Launch Timeline, Price Leaked Ahead of Debut
  3. Motorola Edge 70 Launched With Snapdragon 7 Gen 4 SoC, Slim 5.99mm Profile
  4. Moto G67 Power 5G Launched in India With 7,000mAh Battery: See Price
  5. Samsung Galaxy S26 Ultra Spotted in Leaked Renders With Rounder Corners
  6. Moto G Play (2026), Moto G (2026) With Dimensity 6300 SoC Launched
  7. Realme UI 7.0 Launched With Light Glass Design, AI Features
  8. OnePlus Ace 6 Pro Max Configurations Leaked; May Feature Up to 16GB of RAM
  9. Apple's iOS 26.2 Developer Beta Rolled Out With This New Safety Feature
  1. Realme Will Try to Absorb Increased Cost of Components Ahead of Upcoming Product Launches, Executive Says
  2. Motorola Edge 70 Launched With Snapdragon 7 Gen 4 Chipset, Slim 5.99mm Profile: Price, Specifications
  3. Researchers Unveil How Atomic Entanglement Enhances Light Bursts
  4. Lava Agni 4 Confirmed to Launch in Two Colourways; Tipster Leaks Price Range, Key Features
  5. Google Proposes Play Store Reforms in Settlement With Fortnite Maker Epic Games
  6. Scientists Recreate Cosmic ‘Fireballs’ in Lab to Solve Mystery of Missing Gamma Rays
  7. Realme UI 7.0 Launched With Light Glass Design, AI Notify Brief and AI Gaming Coach: See Eligible Phones, Beta Release Schedule
  8. iOS 26.2 Beta 1 Rolled Out to Developers With Enhanced Safety Alerts, Reminder Alarms
  9. Samsung Galaxy S26 Ultra Spotted in Leaked Design Renders That Hint at Rounder Corners
  10. Call of Duty: Black Ops 7 PC Specifications, Preloading Times Revealed; Activision Confirms Handheld Support
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.