TsarBot is a new Android banking trojan targeting over 750 banking, finance, and cryptocurrency applications worldwide. It spreads via phishing sites and uses overlay attacks to steal credentials by displaying fake login pages over legitimate apps. TsarBot can record and control the screen, capture device lock credentials, and
•8m read time• From cyble.com
Table of contents
Key TakeawaysOverviewTechnical DetailsConclusionOur RecommendationsMITRE ATT&CK® TechniquesIndicators of Compromise (IOCs)Sort: