s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.eventbot

📛 Threat Title

Malware family: Eventbot

Category: Eventbot First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.eventbot`. Printable name: Eventbot.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.eventbot VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.eventbot

IOC database

Type
domain
Value
apk.eventbot
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.eventbot

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.eventbot

References (1)

Remediations (10)

  • web:attack.mitre.org

    EventBot is an Android banking trojan and information stealer that abuses Android's accessibility service to steal data from various applications. [1] EventBot was designed to target over 200 different banking and financial applications, the majority of which are European bank and cryptocurrency exchange applications.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to ThreatFabric, the app overlays 15 financial targets from UK, Italy, and Spain, sniffs 234 apps from banks located in Europe as well as crypto wallets.

  • web:www.appdome.com

    Mobile malware and Trojans like EventBot use overlay attacks to trick users into revealing sensitive information or performing harmful actions inadvertently. Keylogging Prevention - Prevents the use of malicious keyloggers which may be used to intercept two-factor authentication codes or harvest sensitive information.

  • web:www.breachsense.com

    Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.

  • web:www.cybereason.com

    WHAT'S HAPPENING? The Cybereason Nocturnus team is investigating EventBot , a new type of Android mobile are that emerged around March 2020. Eve infostealer that abuses Android's accessibility features to steal user data from financial ages to allow the malware two-factor authentication.

  • web:www.microsoft.com

    Kazuar, a sophisticated malware family attributed to the Russian state actor Secret Blizzard, has been under constant development for years and continues to evolve in support of espionage-focused operations. Over time, Kazuar has expanded from a relatively traditional backdoor into a highly modular peer-to-peer (P2P) botnet ecosystem designed to enable persistent, covert access to target ...

  • web:www.ncsc.gov.uk

    How to defend organisations against malware or ransomware attacks.

  • web:www.pcrisk.com

    What is Eventbot ? Eventbot is a banking Trojan which targets Android users. It attempts to steal sensitive information (such as credit card details, credentials) using overlay technique. It also abuses the Accessibility Service. Eventbot can be the reason behind serious privacy issues, monetary loss and other problems. Eventbot is capable of performing overlay attacks (placing windows over ...

  • web:www.psafe.com

    A pernicious new malware that steals Android mobile banking data has been discovered, and it's targeting Android users throughout Europe and the United States. " Eventbot " leverages Android accessibility to reap private data from financial applications.

  • web:www.securityweek.com

    Cybercrime New 'EventBot' Android Malware Targets Nearly 300 Financial Apps A newly discovered piece of Android malware is targeting the users of close to 300 financial applications across the United States and Europe, Cybereason Nocturnus security researchers warn.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.