New EventBot Malware Targets Android Banking and Crypto Apps

A sophisticated new Android malware named EventBot steals passwords and two-factor codes from over 200 banking and cryptocurrency apps. The threat exploits accessibility features to quietly siphon funds and remains actively under development.

Security researchers at Cybereason warn that a sophisticated new Android malware named EventBot actively targets over 200 banking and cryptocurrency apps. The malware disguises itself as legitimate software like Adobe Flash or Microsoft Word to trick users into installing it. Once on the device, EventBot abuses Android's built-in accessibility features to gain deep access to the operating system.

The malware quietly records every tap and key press, reads notifications from other installed apps, and intercepts two-factor authentication text messages. By stealing both passwords and 2FA codes from services like PayPal, Coinbase, and HSBC, hackers easily break into accounts and steal funds. EventBot also evolves rapidly, with its creators updating the malware every few days to add new features like improved encryption and the ability to grab a user's device lock code.

Because the malicious code appears to be written entirely from scratch without reusing older malware, experts note a high level of sophistication and investment by the developers. This threat highlights a growing trend of hackers targeting mobile users who keep their most sensitive financial services on their phones. As Android malware continues to rise, device owners face increasing risks from these highly advanced attacks.

Read More at the original source →