logo

New Android Banking Trojan Targets More Than 750 Financial and Crypto Apps

ID: 45dfb61a-19bb-54ee-ba69-9dd767210ed3

STIX ID: report--45dfb61a-19bb-54ee-ba69-9dd767210ed3

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2025-03-31

Date Updated: 2026-04-23

Author: Paul Shread

...
...

Cyble researchers uncovered TsarBot, an Android banking trojan spread through phishing sites (e.g., solphoton.io, solphoton.app, cashraven.online) that installs an APK (implant.apk) and abuses Accessibility services and WebSocket C2 channels to execute overlay attacks, screen capture, keylogging, SMS interception and lock-grabbing against over 750 banking, finance, crypto, payment, social media and e‑commerce apps to steal credentials and perform on-device fraud.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.