Latest News

Meet EventBot, a new Android malware that steals banking passwords and two-factor codes
Friday, May 1, 2020 IST
Meet EventBot, a new Android malware that steals banking passwords and two-factor codes

Security researchers are sounding the alarm over a newly discovered Android  malware that targets banking apps and cryptocurrency wallets.
 

 
 

The malware, which researchers at security firm Cybereason  recently discovered and called EventBot, masquerades as a legitimate Android app — like Adobe Flash or Microsoft Word for Android — which abuses Android’s in-built accessibility features to obtain deep access to the device’s operating system.
 
Once installed — either by an unsuspecting user or by a malicious person with access to a victim’s phone — the EventBot-infected fake app quietly siphons off passwords for more than 200 banking and cryptocurrency apps — including PayPal, Coinbase, CapitalOne and HSBC — and intercepts and two-factor authentication text message codes.
 
With a victim’s password and two-factor code, the hackers can break into bank accounts, apps and wallets, and steal a victim’s funds.
 
“The developer behind Eventbot has invested a lot of time and resources into creating the code, and the level of sophistication and capabilities is really high,” Assaf Dahan, head of threat research at Cybereason, told TechCrunch.
 
The malware quietly records every tap and key press, and can read notifications from other installed apps, giving the hackers a window into what’s happening on a victim’s device.
 
Over time, the malware siphons off banking and cryptocurrency app passwords back to the hackers’ server.
 
The researchers said that EventBot remains a work in progress. Over a period of several weeks since its discovery in March, the researchers saw the malware iteratively update every few days to include new malicious features. At one point the malware’s creators improved the encryption scheme it uses to communicate with the hackers’ server, and included a new feature that can grab a user’s device lock code, likely to allow the malware to grant itself higher privileges to the victim’s device like payments and system settings.
 

 
 

But while the researchers are stumped as to who is behind the campaign, their research suggests the malware is brand new.
 
“Thus far, we haven’t observed clear cases of copy-paste or code reuse from other malware and it seems to have been written from scratch,” said Dahan.
 
Android malware is not new, but it’s on the rise. Hackers and malware operators have increasingly targeted mobile users because many device owners have their banking apps, social media, and other sensitive services on their device. Google has improved Android security in recent years by screening apps in its app store and proactively blocking third-party apps to cut down on malware — with mixed results. Many malicious apps have evaded Google’s detection.
 
Cybereason said it has not yet seen EventBot on Android’s app store or in active use in malware campaigns, limiting the exposure to potential victims — for now.
 
But the researchers said users should avoid untrusted apps from third-party sites and stores, many of which don’t screen their apps for malware.
 

 
 
 
 
 

Related Topics

 
 
 

Trending News & Articles

 Article
How to make you car as silent as a Rolls Royce inside

Rolls Royce cars are extremely luxurious. While there are many expensive pieces of equipment in Rolls Royce cars, their most relaxing feature is the silence that ...

Recently posted . 3K views . 2 min read
 

 Article
India's Top 5 Mobile Charger manufacturer Brand 2019

The following list of India's Top 5 Mobile Charger manufacture Brand 2019  

Recently posted . 3K views . 0 min read
 

 Article
Mahindra XUV300 vs Maruti Brezza, Ford EcoSport, Tata Nexon – Price

XUV300 is the latest entrant in the compact SUV segment.

Recently posted . 3K views . 0 min read
 

 Article
Tata Harrier’s 7-seater Version H7X Will Be Quite Different – Report

Tata Harrier’s three-row seat version in works, details out  

Recently posted . 2K views . 0 min read
 

 
 

More in Electronics & Gadgets

 Article
New Hyundai Santro: Key Features Explained

The all-new Hyundai Santro is an evolution over the old hatchback and revives the age-old brand in Hyundai's line-up.  

Recently posted. 1K views . 1 min read
 

 Article
Redmi Note 7 Pro launched in India with 48MP camera, 128GB storage: Check price, specs and availability

Redmi Note 7 Pro made its global debut on Thursday afternoon. Check its price, specs and availability.

Recently posted. 728 views . 0 min read
 

 Article
Indian Government Launches ‘UMANG’- An App to Access All Government Services: Everything You Need to Know

Indian Government is trying to keep up the ‘Digital India‘ initiative alive. Yesterday, at the fifth edition of the Global Conference on Cyberspace in N...

Recently posted. 693 views . 3 min read
 

 Video
Video



Recently posted . 625 views
 

 Reviews
Top 10 Best Earphones under 1000 – Comparison & Review



Recently posted . 1K views . 256 min read
 

 Article
NOW, YOU CAN JAILBREAK AN IPHONE USING A ROOTED ANDROID

The Checkra1n utility that is in use to jailbreak certain iPhones can now be used from a rooted Android smartphone. A practice that could have interest in rare ca...

Recently posted. 734 views . 1 min read
 

 Article
Samsung Unveils Graphene Ball Tech, Says Its Batteries Can Be Fully Charged in 12 Minutes

Graphene considered a wonder material, with many potential applications Graphene ball-based batteries could hold 45 percen...

Recently posted. 717 views . 2 min read
 

 
 
 

   Prashnavali

  Thought of the Day

थोड़ा गरूर भी जरूरी है🌻 जीने के लिये ज्यादा झुक कर मिलो तो दुनिया पीठ का पायदान बना लेती है 🌹🌹🌻🌻 सुप्रभात आपका दिन शुभ हो🌻 💐💐🌻
Anonymous

Be the first one to comment on this story

Close
Post Comment
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST


ads
Back To Top