This sophisticated new Android trojan threatens hundreds of financial apps

Android
(Image credit: Shutterstock)

Researchers have discovered a sophisticated new Android trojan that bypasses security measures and scrapes data from financial applications.

First identified in March, the EventBot banking trojan abuses Android’s accessibility features to harvest financial data and intercept SMS messages, allowing the malware to circumvent two-factor authentication.

According to Cybereason, the firm responsible for the discovery, EventBot targets over 200 financial applications, spanning banking, money transfer and cryptocurrency wallet services.

Affected applications include those operated by major players such as HSBC, Barclays, Revolut, Paypal and TransferWise - but many more are thought to be at risk.

Android banking trojan

Despite its relative infancy, EventBot is said to exhibit a high level of sophistication and is also under active development, with developers publishing more advanced iterations every few days. The malware appears to have been built from the ground up, with “code that differs significantly from previous Android malware,” according to security analysts at Cybereason.

EventBot does not currently feature on the Google Play Store, suggesting its operators are distributing the malware via illegitimate application stores and rogue websites. The trojan has been seen to masquerade as popular applications such as Microsoft Word and Adobe Flash Player.

Beyond stealing financial data, the trojan can also access system information, personal data, passwords and keystrokes - all of which can be used to hijack transactions and other online accounts.

“Cybereason believes EventBot could be the next influential mobile malware because of the time the developer has already invested into creating the code...the level of sophistication is really high,” said Assaf Dahan, Head of Threat Research at Cybereason.

“By accessing and stealing this data, Eventbot has the potential to access key business data, including financial information. Mobile malware is no laughing matter and is a significant risk for organisations and consumers alike,” he added.

To minimise exposure to the new EventBot trojan, Android users are advised to download the latest software updates from legitimate sources, ensure Google Play Protect remains active at all times and exercise critical thinking when setting application permissions.

Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras