Tsar is a threat actor name referenced in connection with mobile-malware activity. High-confidence reporting available here only establishes that the group was dubbed “Tsar team” and was associated with the use of mobile malware. No corroborated details are available in the supplied facts regarding its origin, victimology, operational timeframe, tooling beyond mobile malware, or specific tactics and objectives. The available evidence is insufficient to confidently map aliases, sub-groups, geographic attribution, targeting patterns, or broader intrusion lifecycle behaviors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Separate Russia-linked intrusion team referenced as conducting campaigns involving mobile malware, targeting intelligence communities, militaries, defense contractors, media, NGOs, multilateral organizations, and also jihadists/rebels in Chechnya.
Separate Russia-linked intrusion team referenced as conducting espionage campaigns using mobile malware, targeting intelligence communities, militaries, defense contractors, media, NGOs, multilateral organizations, and also jihadists/rebels in Chechnya.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.