logo

TsarBot Trojan Hits 750+ Banking & Crypto Apps!

ID: ba023bd5-1132-560c-aac8-513558fc5497

STIX ID: report--ba023bd5-1132-560c-aac8-513558fc5497

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-04-01

Date Updated: 2026-07-20

...
...

Cyble Research discovered 'TsarBot,' a sophisticated Android banking Trojan delivered via phishing sites and a dropper disguised as Google Play Services; it targets over 750 banking, finance, crypto, and e‑commerce apps, abuses Accessibility and Media Projection to perform overlay phishing, screen recording, remote on-device control and lock‑grabbing, communicates with a C2 at 95.181.173.76 over multiple WebSocket ports, and includes numerous IOCs (file hashes, phishing and injection URLs) and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.