TF-MAL-apk.eventbot
📛 Threat Title
Malware family: Eventbot
Description
ThreatFox malware family `apk.eventbot`. Printable name: Eventbot.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.eventbot
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.eventbot
IOC database
- Type
- domain
- Value
apk.eventbot- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.eventbot
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.eventbot
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
EventBot is an Android banking trojan and information stealer that abuses Android's accessibility service to steal data from various applications. [1] EventBot was designed to target over 200 different banking and financial applications, the majority of which are European bank and cryptocurrency exchange applications.
-
web:malpedia.caad.fkie.fraunhofer.de
According to ThreatFabric, the app overlays 15 financial targets from UK, Italy, and Spain, sniffs 234 apps from banks located in Europe as well as crypto wallets.
-
web:www.appdome.com
Mobile malware and Trojans like EventBot use overlay attacks to trick users into revealing sensitive information or performing harmful actions inadvertently. Keylogging Prevention - Prevents the use of malicious keyloggers which may be used to intercept two-factor authentication codes or harvest sensitive information.
-
web:www.breachsense.com
Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.
-
web:www.cybereason.com
WHAT'S HAPPENING? The Cybereason Nocturnus team is investigating EventBot , a new type of Android mobile are that emerged around March 2020. Eve infostealer that abuses Android's accessibility features to steal user data from financial ages to allow the malware two-factor authentication.
-
web:www.microsoft.com
Kazuar, a sophisticated malware family attributed to the Russian state actor Secret Blizzard, has been under constant development for years and continues to evolve in support of espionage-focused operations. Over time, Kazuar has expanded from a relatively traditional backdoor into a highly modular peer-to-peer (P2P) botnet ecosystem designed to enable persistent, covert access to target ...
-
web:www.ncsc.gov.uk
How to defend organisations against malware or ransomware attacks.
-
web:www.pcrisk.com
What is Eventbot ? Eventbot is a banking Trojan which targets Android users. It attempts to steal sensitive information (such as credit card details, credentials) using overlay technique. It also abuses the Accessibility Service. Eventbot can be the reason behind serious privacy issues, monetary loss and other problems. Eventbot is capable of performing overlay attacks (placing windows over ...
-
web:www.psafe.com
A pernicious new malware that steals Android mobile banking data has been discovered, and it's targeting Android users throughout Europe and the United States. " Eventbot " leverages Android accessibility to reap private data from financial applications.
-
web:www.securityweek.com
Cybercrime New 'EventBot' Android Malware Targets Nearly 300 Financial Apps A newly discovered piece of Android malware is targeting the users of close to 300 financial applications across the United States and Europe, Cybereason Nocturnus security researchers warn.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.