TsarBot Trojan Hits 750+ Banking & Crypto Apps!
ID: ba023bd5-1132-560c-aac8-513558fc5497
STIX ID: report--ba023bd5-1132-560c-aac8-513558fc5497
Feed Name: Cyble Blog
Cyble Research discovered 'TsarBot,' a sophisticated Android banking Trojan delivered via phishing sites and a dropper disguised as Google Play Services; it targets over 750 banking, finance, crypto, and e‑commerce apps, abuses Accessibility and Media Projection to perform overlay phishing, screen recording, remote on-device control and lock‑grabbing, communicates with a C2 at 95.181.173.76 over multiple WebSocket ports, and includes numerous IOCs (file hashes, phishing and injection URLs) and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
