TF-MAL-apk.tsarbot
📛 Threat Title
Malware family: TsarBot
Description
ThreatFox malware family `apk.tsarbot`. Printable name: TsarBot.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.tsarbot
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.tsarbot
IOC database
- Type
- domain
- Value
apk.tsarbot- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.tsarbot
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.tsarbot
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cybernoz.com
A newly discovered Android banking malware named TsarBot is targeting over 750 applications globally, including banking, finance, cryptocurrency, and e-commerce platforms. Identified by Cyble Research and Intelligence Labs (CRIL), TsarBot employs sophisticated overlay attacks and phishing techniques to intercept sensitive credentials and execute fraudulent transactions. TsarBot spreads through ...
-
web:cybersecuritynews.com
A newly discovered Android banking malware named TsarBot is targeting over 750 applications globally, including banking, finance, cryptocurrency, and e-commerce platforms.
-
web:cyble.com
Cyble analyzes TsarBot , a newly identified Android banking Trojan that employs overlay attacks to target over 750 banking, financial, and cryptocurrency applications worldwide.
-
web:malpedia.caad.fkie.fraunhofer.de
TsarBot can record and remotely control the screen, executing fraud by simulating user actions such as swiping, tapping, and entering credentials while hiding malicious activities using a black overlay screen. It captures device lock credentials using a fake lock screen to gain full control.
-
web:www.broadcom.com
TsarBot is a new Android banking trojan reported to be targeting over 750 different banking, financial and cryptocurrency-related applications. The malware is spread via phishing websites disguised as legitimate financial portals.
-
web:www.bugsfighter.com
What is TsarBot Banking Trojan TsarBot Banking Trojan is a sophisticated piece of malware specifically designed to target Android devices, functioning primarily as a banking trojan. This malicious software is capable of infiltrating over 750 finance-related applications, aiming to extract sensitive user data such as login credentials, credit card numbers, and personal identifiable information ...
-
web:www.forbes.com
Do not click OK to agree this app update. "By abusing Accessibility services and WebSocket communication," Cyble warns, " TsarBot underscores the persistent threat posed by banking malware .
-
web:www.itfunk.org
Android users across the globe are facing an increasingly sophisticated cyber threat known as TsarBot - a multi-functional malware specifically engineered to steal financial information by targeting more than 750 banking, cryptocurrency, e-commerce, and social media applications.
-
web:www.pcrisk.com
What kind of malware is TsarBot ? TsarBot is a multi-functional malware targeting Android devices. Specifically, it is a banking trojan designed to obtain information associated with over 750 finance-related applications from various regions.
-
web:zimperium.com
TsarBot , CopyBara, and Hook dominate: These three malware families collectively target more than 60% of the global banking and fintech apps analyzed. Fraud evolving into extortion: Nearly half of the malware families analyzed have financial extortion capabilities including ransomware capabilities, allowing attackers to encrypt files on the device.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.