s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.tsarbot

📛 Threat Title

Malware family: TsarBot

Category: TsarBot First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.tsarbot`. Printable name: TsarBot.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.tsarbot VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.tsarbot

IOC database

Type
domain
Value
apk.tsarbot
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.tsarbot

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.tsarbot

References (1)

Remediations (10)

  • web:cybernoz.com

    A newly discovered Android banking malware named TsarBot is targeting over 750 applications globally, including banking, finance, cryptocurrency, and e-commerce platforms. Identified by Cyble Research and Intelligence Labs (CRIL), TsarBot employs sophisticated overlay attacks and phishing techniques to intercept sensitive credentials and execute fraudulent transactions. TsarBot spreads through ...

  • web:cybersecuritynews.com

    A newly discovered Android banking malware named TsarBot is targeting over 750 applications globally, including banking, finance, cryptocurrency, and e-commerce platforms.

  • web:cyble.com

    Cyble analyzes TsarBot , a newly identified Android banking Trojan that employs overlay attacks to target over 750 banking, financial, and cryptocurrency applications worldwide.

  • web:malpedia.caad.fkie.fraunhofer.de

    TsarBot can record and remotely control the screen, executing fraud by simulating user actions such as swiping, tapping, and entering credentials while hiding malicious activities using a black overlay screen. It captures device lock credentials using a fake lock screen to gain full control.

  • web:www.broadcom.com

    TsarBot is a new Android banking trojan reported to be targeting over 750 different banking, financial and cryptocurrency-related applications. The malware is spread via phishing websites disguised as legitimate financial portals.

  • web:www.bugsfighter.com

    What is TsarBot Banking Trojan TsarBot Banking Trojan is a sophisticated piece of malware specifically designed to target Android devices, functioning primarily as a banking trojan. This malicious software is capable of infiltrating over 750 finance-related applications, aiming to extract sensitive user data such as login credentials, credit card numbers, and personal identifiable information ...

  • web:www.forbes.com

    Do not click OK to agree this app update. "By abusing Accessibility services and WebSocket communication," Cyble warns, " TsarBot underscores the persistent threat posed by banking malware .

  • web:www.itfunk.org

    Android users across the globe are facing an increasingly sophisticated cyber threat known as TsarBot - a multi-functional malware specifically engineered to steal financial information by targeting more than 750 banking, cryptocurrency, e-commerce, and social media applications.

  • web:www.pcrisk.com

    What kind of malware is TsarBot ? TsarBot is a multi-functional malware targeting Android devices. Specifically, it is a banking trojan designed to obtain information associated with over 750 finance-related applications from various regions.

  • web:zimperium.com

    TsarBot , CopyBara, and Hook dominate: These three malware families collectively target more than 60% of the global banking and fintech apps analyzed. Fraud evolving into extortion: Nearly half of the malware families analyzed have financial extortion capabilities including ransomware capabilities, allowing attackers to encrypt files on the device.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.