New Android Banking Trojan Targets More Than 750 Financial and Crypto Apps
ID: 45dfb61a-19bb-54ee-ba69-9dd767210ed3
STIX ID: report--45dfb61a-19bb-54ee-ba69-9dd767210ed3
Feed Name: The Cyber Express
Threat Score
Cyble researchers uncovered TsarBot, an Android banking trojan spread through phishing sites (e.g., solphoton.io, solphoton.app, cashraven.online) that installs an APK (implant.apk) and abuses Accessibility services and WebSocket C2 channels to execute overlay attacks, screen capture, keylogging, SMS interception and lock-grabbing against over 750 banking, finance, crypto, payment, social media and e‑commerce apps to steal credentials and perform on-device fraud.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
