Skip to content

Botnet

TsarBot

According to Cyble, this is a banking trojan that targets over 750 applications globally, including banking, finance, cryptocurrency, and e-commerce apps.

TsarBot is a Android botnet.

Background

Cyble reports that this banking trojan goes after more than 750 applications worldwide, spanning banking, finance, cryptocurrency, and e-commerce. It reaches victims through phishing sites posing as real financial platforms and installs via a dropper that pretends to be Google Play Services. Using overlay attacks, it presents counterfeit login pages on top of legitimate apps to harvest banking credentials, card numbers, and other logins. TsarBot can record and remotely operate the screen, committing fraud by mimicking user gestures such as swiping, tapping, and typing credentials while masking its actions behind a black overlay. It also grabs the device lock credentials through a fake lock screen to obtain full control, and it talks to its C&C server over WebSocket on multiple ports to fetch commands, exfiltrate stolen data, and drive on-device fraud in real time.


Source: Malpedia (Fraunhofer FKIE).