The Curated Daily
← Back to the archiveDispatch · 6 min read
Dispatch

A new Android malware from Google

By the editors·Thursday, July 2, 2026·6 min read
A smartphone displaying Google Search trends on a table at night.
Photograph by Click Jeth · Pexels

A new and sophisticated Android banking trojan, dubbed 'TeaBot' (also known as Anubis), is making waves in the cybersecurity world. This malware poses a significant threat to individuals who rely on mobile banking and financial applications. Unlike some malware that aims for broad data collection, TeaBot is laser-focused on stealing credentials for banking apps, potentially draining accounts and causing significant financial harm. This article will delve into the details of TeaBot, how it operates, what makes it dangerous, and most importantly, how you can protect yourself.

What is TeaBot and How Does It Work?

TeaBot isn’t a single app you directly download; it's a dropper – a malicious application disguised as something legitimate, such as a system update, a PDF reader, or even a fake file manager. Its primary function is to download and install the actual banking trojan. This multi-stage infection process makes it harder to detect than malware delivered directly.

Here’s a breakdown of how TeaBot typically operates:

  1. Infection Vector: TeaBot spreads primarily through smishing – SMS phishing. Users receive text messages containing a link to download the malicious dropper app. These messages often appear to come from legitimate sources, like your bank or a delivery service, creating a sense of urgency and trust.
  2. Dropper Installation: Once the dropper app is installed, it requests permissions that seem innocuous, such as access to notifications or running in the background. These permissions are crucial for its operation.
  3. Trojan Download & Installation: The dropper silently downloads the actual TeaBot banking trojan in the background. This payload is the real threat.
  4. Credential Theft: The TeaBot trojan then monitors your device activity, specifically looking for when you open banking or financial apps.
  5. Overlay Attacks: When a targeted app is launched, TeaBot displays a fake login screen over the legitimate one. This is known as an overlay attack. Anything you type – your username, password, and potentially even two-factor authentication codes – is captured by the malware and sent to the attackers.
  6. Data Exfiltration: The stolen credentials and other sensitive information are then transmitted to a command-and-control (C&C) server controlled by the cybercriminals.

Why is TeaBot So Dangerous?

Several factors contribute to the heightened danger posed by TeaBot:

  • Sophisticated Evasion Techniques: TeaBot employs multiple techniques to avoid detection, including obfuscation of its code and using legitimate tools for malicious purposes. It's constantly evolving, making it a moving target for security researchers.
  • Targeted Attacks: TeaBot isn’t indiscriminate. It specifically targets a wide range of banking and financial applications, particularly those popular in Europe, but its reach is expanding.
  • Accessibility Services Abuse: TeaBot leverages Android’s Accessibility Services – features designed to help users with disabilities – to perform actions like reading screen content, simulating taps, and interacting with other apps. This makes it extremely difficult to detect as it appears to be a legitimate function of the device.
  • Geographic Expansion: Originally focused on Europe, TeaBot's developers are actively expanding its targeting to other regions, including North America and South America.
  • Regular Updates & New Features: The developers behind TeaBot consistently update the malware with new features and evasion techniques, making it harder to combat. Recent updates have included the ability to steal SMS messages, adding another layer to their attack.

Identifying if You're Infected: Signs to Look For

Detecting TeaBot infection can be tricky, as it operates stealthily. However, be alert for these signs:

  • Unusual App Permissions: Review recently installed apps and pay attention to any requesting excessive or unnecessary permissions.
  • Strange SMS Messages: Be wary of unsolicited text messages asking you to download apps or click on links, especially if they create a sense of urgency.
  • Unexpected Battery Drain: Malware running in the background can significantly drain your device's battery.
  • Increased Data Usage: TeaBot transmitting stolen data consumes data. Monitor your data usage for unexpected spikes.
  • Performance Issues: A compromised device may run slower than usual.
  • Pop-up Overlays: Although subtle, be mindful of unexpected pop-ups or overlays appearing when opening banking apps.

How to Protect Yourself from TeaBot

Prevention is the best defense against TeaBot and other Android malware. Here are crucial steps you can take:

  • Be Extremely Cautious with SMS Links: Never click on links or download files from unsolicited text messages, even if they appear to be from trusted sources. Contact the organization directly through official channels if you're unsure.
  • Enable Google Play Protect: Google Play Protect is built into Android and scans apps for malicious behavior. Ensure it’s enabled and up-to-date.
  • Install a Reputable Mobile Security App: Consider using a third-party mobile security app from a trusted provider. These apps offer advanced threat detection and protection features. is a highly-rated option.
  • Keep Your Android OS and Apps Updated: Software updates often include security patches that address vulnerabilities exploited by malware.
  • Review App Permissions: Regularly review the permissions granted to your installed apps and revoke any that seem unnecessary or suspicious.
  • Use a Strong Device Lock: Set a strong PIN, password, or biometric lock on your device to prevent unauthorized access.
  • Avoid Sideloading Apps: Sideloading – installing apps from sources other than the Google Play Store – significantly increases your risk of infection. Only install apps from the official app store.
  • Be Wary of Public Wi-Fi: Avoid using public Wi-Fi networks for sensitive transactions like online banking. If you must use public Wi-Fi, use a Virtual Private Network (VPN) to encrypt your internet traffic.

What To Do If You Suspect Infection

If you believe your device may be infected with TeaBot, take these steps immediately:

  1. Disconnect from the Internet: This will prevent the malware from transmitting further data.
  2. Run a Full Scan with a Mobile Security App: Use a reputable mobile security app to scan your device for malware.
  3. Change Your Banking Passwords: Change your passwords for all of your banking and financial accounts from a clean device (a computer or a different smartphone you trust).
  4. Contact Your Bank: Inform your bank about the potential security breach and monitor your accounts for any unauthorized activity.
  5. Factory Reset (Last Resort): If other methods fail, a factory reset will erase all data on your device and restore it to its original settings. Back up important data first, but be aware that the backup may contain the malware, so proceed with caution.
  6. Consider Professional Help: If you're unsure how to proceed, seek assistance from a cybersecurity professional.

The Future of Android Malware

TeaBot represents a growing trend of sophisticated mobile malware targeting financial data. As technology evolves, cybercriminals will continue to develop new and innovative ways to exploit vulnerabilities and steal sensitive information. Staying informed and proactive about mobile security is crucial to protecting yourself in the digital age. Regularly reviewing your security practices and being vigilant against phishing attacks are your best defenses.

Disclaimer:

This article contains affiliate links to products we recommend. If you click on a link and make a purchase, we may receive a small commission at no extra cost to you. This helps support our website and allows us to continue providing helpful content. We only recommend products we believe in and have thoroughly researched. The information provided in this article is for general guidance only and should not be considered professional security advice. Always consult with a cybersecurity professional for personalized advice. https://example.com/ is an example of an affiliate product.

Pass it onX·LinkedIn·Reddit·Email
The Sunday note

If this was your kind of read.

Sign up for the morning email — short, hand-written, and sent only when there's something worth your time.

Free, sent from a person, not a system. Unsubscribe in one click whenever.

Keep reading

The archive →