{"id":8682,"date":"2020-05-01T19:40:00","date_gmt":"2020-05-01T19:40:00","guid":{"rendered":"https:\/\/icrowdnewswire.com\/?p=2538168"},"modified":"2020-05-01T19:40:00","modified_gmt":"2020-05-01T19:40:00","slug":"meet-eventbot-a-new-android-malware-that-steals-banking-passwords-and-two-factor-codes","status":"publish","type":"post","link":"https:\/\/ipsnews.net\/business\/2020\/05\/01\/meet-eventbot-a-new-android-malware-that-steals-banking-passwords-and-two-factor-codes\/","title":{"rendered":"Meet EventBot, a new Android malware that steals banking passwords and two-factor codes"},"content":{"rendered":"<p><img decoding=\"async\" class=\"article__featured-image article__featured-image--block breakout\" src=\"https:\/\/techcrunch.com\/wp-content\/uploads\/2020\/04\/GettyImages-924145016.jpg?w=730&amp;crop=1\" sizes=\"(max-width: 730px) 100vw, (max-width: 1600px) 75vw, 1390px\" srcset=\"https:\/\/techcrunch.com\/wp-content\/uploads\/2020\/04\/GettyImages-924145016.jpg?w=400&amp;crop=1 400w, https:\/\/techcrunch.com\/wp-content\/uploads\/2020\/04\/GettyImages-924145016.jpg?w=730&amp;crop=1 730w, https:\/\/techcrunch.com\/wp-content\/uploads\/2020\/04\/GettyImages-924145016.jpg?w=990&amp;crop=1 990w, https:\/\/techcrunch.com\/wp-content\/uploads\/2020\/04\/GettyImages-924145016.jpg?w=1390&amp;crop=1 1390w\" alt=\"Samsung Responds to iPhone X With S9 Launch\" \/><\/p>\n<div class=\"article-content\">\n<p id=\"speakable-summary\">Security researchers are sounding the alarm over a newly discovered&nbsp;<a class=\"crunchbase-link\" href=\"https:\/\/crunchbase.com\/organization\/android\" target=\"_blank\" rel=\"noopener noreferrer\" data-type=\"organization\" data-entity=\"android\">Android&nbsp;<\/a>&nbsp;malware that targets banking apps and cryptocurrency wallets.<\/p>\n<p>The malware, which researchers at security firm&nbsp;<a class=\"crunchbase-link\" href=\"https:\/\/crunchbase.com\/organization\/cybereason\" target=\"_blank\" rel=\"noopener noreferrer\" data-type=\"organization\" data-entity=\"cybereason\">Cybereason&nbsp;<\/a>&nbsp;recently discovered and&nbsp;<a href=\"http:\/\/www.cybereason.com\/blog\/eventbot-a-new-mobile-banking-trojan-is-born\">called EventBot<\/a>, masquerades as a legitimate Android app &mdash; like Adobe Flash or Microsoft Word for Android &mdash; which abuses Android&rsquo;s in-built accessibility features to obtain deep access to the device&rsquo;s operating system.<\/p>\n<p>Once installed &mdash; either by an unsuspecting user or by a malicious person with access to a victim&rsquo;s phone &mdash;&nbsp;the EventBot-infected fake app quietly siphons off passwords for more than 200 banking and cryptocurrency apps &mdash; including PayPal, Coinbase, CapitalOne and HSBC &mdash; and intercepts and two-factor authentication text message codes.<\/p>\n<p>With a victim&rsquo;s password and two-factor code, the hackers can break into bank accounts, apps and wallets, and steal a victim&rsquo;s funds.<\/p>\n<p>&ldquo;The developer behind Eventbot has invested a lot of time and resources into creating the code, and the level of sophistication and capabilities is really high,&rdquo; Assaf Dahan, head of threat research at Cybereason, told TechCrunch.<\/p>\n<p>The malware quietly records every tap and key press, and can read notifications from other installed apps, giving the hackers a window into what&rsquo;s happening on a victim&rsquo;s device.<\/p>\n<p>Over time, the malware siphons off banking and cryptocurrency app passwords back to the hackers&rsquo; server.<\/p>\n<p>The researchers said that EventBot remains a work in progress. Over a period of several weeks since its discovery in March, the researchers saw the malware iteratively update every few days to include new malicious features. At one point the malware&rsquo;s creators improved the encryption scheme it uses to communicate with the hackers&rsquo; server, and included a new feature that can grab a user&rsquo;s device lock code, likely to allow the malware to grant itself higher privileges to the victim&rsquo;s device like payments and system settings.<\/p>\n<p>But while the researchers are stumped as to who is behind the campaign, their research suggests the malware is brand new.<\/p>\n<p>&ldquo;Thus far, we haven&rsquo;t observed clear cases of copy-paste or code reuse from other malware and it seems to have been written from scratch,&rdquo; said Dahan.<\/p>\n<p>Android malware is not new, but it&rsquo;s on the rise. Hackers and malware operators have increasingly targeted mobile users because many device owners have their banking apps, social media, and other sensitive services on their device. Google has improved Android security in recent years by&nbsp;<a href=\"https:\/\/techcrunch.com\/2019\/11\/06\/google-play-android-apps-security\/\">screening apps<\/a>&nbsp;in its app store and proactively&nbsp;<a href=\"https:\/\/techcrunch.com\/2019\/08\/16\/android-users-tricked-adware-apps\/\">blocking third-party apps<\/a>&nbsp;to cut down on malware &mdash; with mixed results. Many malicious apps&nbsp;<a href=\"https:\/\/techcrunch.com\/2019\/10\/24\/millions-dozens-android-apps-adware\/\">have evaded<\/a>&nbsp;Google&rsquo;s detection.<\/p>\n<p>Cybereason said it has not yet seen EventBot on Android&rsquo;s app store or in active use in malware campaigns, limiting the exposure to potential victims &mdash; for now.<\/p>\n<p>But the researchers said users should avoid untrusted apps from third-party sites and stores, many of which don&rsquo;t screen their apps for malware.<\/p>\n<div class=\"embed breakout\">&nbsp;<\/div>\n<\/div>\n<p class=\"tags\">\n<div><strong>See Campaign: <\/strong><a href=\"https:\/\/crunchbase.com\/organization\/android\" target=\"_blank\">https:\/\/crunchbase.com\/organization\/android<\/a><br \/><b>Contact Information:<\/b><br \/>Zack Whittaker<\/p>\n<p><b>Tags:<\/b><br \/><a href=\"\"><\/a>, <a href=\"https:\/\/icrowdnewswire.com\/category\/news-category\/wire\/\" rel=\"category tag\">Wire<\/a>, <a href=\"https:\/\/icrowdnewswire.com\/category\/global-regions\/united-states\/\" rel=\"category tag\">United States<\/a>, <a href=\"https:\/\/icrowdnewswire.com\/category\/language\/english\/\" rel=\"category tag\">English<\/a><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"\" alt=\"image\" width=\"400\" height=\"300\" class=\"cwdfimg\" \/><\/div>\n<div>\n<h3>Contact Information:<\/h3>\n<p>Zack Whittaker<\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Security researchers are sounding the alarm over a newly discovered&nbsp;Android&nbsp;&nbsp;malware that targets banking apps and cryptocurrency wallets. The malware, which researchers at security firm&nbsp;Cybereason&nbsp;&nbsp;recently discovered and&nbsp;called EventBot, masquerades as a legitimate Android app &mdash; like Adobe Flash or Microsoft Word for Android &mdash; which abuses Android&rsquo;s in-built accessibility features to obtain deep access to the &hellip; <a href=\"https:\/\/icrowdnewswire.com\/2020\/05\/01\/meet-eventbot-a-new-android-malware-that-steals-banking-passwords-and-two-factor-codes\/\">Continue reading <span>Meet EventBot, a new Android malware that steals banking passwords and two-factor codes<\/span><\/a> <a href=\"https:\/\/ipsnews.net\/business\/2020\/05\/01\/meet-eventbot-a-new-android-malware-that-steals-banking-passwords-and-two-factor-codes\/\" class=\"more-link\">Continue Reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":19,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,22,54],"tags":[],"class_list":["post-8682","post","type-post","status-publish","format-standard","hentry","category-english","category-united-states","category-wire"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Meet EventBot, a new Android malware that steals banking passwords and two-factor codes - Business<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"http:\/\/ipsnews.net\/business\/2020\/05\/01\/meet-eventbot-a-new-android-malware-that-steals-banking-passwords-and-two-factor-codes\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Meet EventBot, a new Android malware that steals banking passwords and two-factor codes - Business\" \/>\n<meta property=\"og:description\" content=\"Security researchers are sounding the alarm over a newly discovered&nbsp;Android&nbsp;&nbsp;malware that targets banking apps and cryptocurrency wallets. The malware, which researchers at security firm&nbsp;Cybereason&nbsp;&nbsp;recently discovered and&nbsp;called EventBot, masquerades as a legitimate Android app &mdash; like Adobe Flash or Microsoft Word for Android &mdash; which abuses Android&rsquo;s in-built accessibility features to obtain deep access to the &hellip; Continue reading Meet EventBot, a new Android malware that steals banking passwords and two-factor codes Continue Reading &rarr;\" \/>\n<meta property=\"og:url\" content=\"http:\/\/ipsnews.net\/business\/2020\/05\/01\/meet-eventbot-a-new-android-malware-that-steals-banking-passwords-and-two-factor-codes\/\" \/>\n<meta property=\"og:site_name\" content=\"Business\" \/>\n<meta property=\"article:published_time\" content=\"2020-05-01T19:40:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techcrunch.com\/wp-content\/uploads\/2020\/04\/GettyImages-924145016.jpg?w=730&amp;crop=1\" \/>\n<meta name=\"author\" content=\"Aneesa\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Aneesa\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"http:\/\/ipsnews.net\/business\/2020\/05\/01\/meet-eventbot-a-new-android-malware-that-steals-banking-passwords-and-two-factor-codes\/\",\"url\":\"http:\/\/ipsnews.net\/business\/2020\/05\/01\/meet-eventbot-a-new-android-malware-that-steals-banking-passwords-and-two-factor-codes\/\",\"name\":\"Meet EventBot, a new Android malware that steals banking passwords and two-factor codes - Business\",\"isPartOf\":{\"@id\":\"https:\/\/ipsnews.net\/business\/#website\"},\"primaryImageOfPage\":{\"@id\":\"http:\/\/ipsnews.net\/business\/2020\/05\/01\/meet-eventbot-a-new-android-malware-that-steals-banking-passwords-and-two-factor-codes\/#primaryimage\"},\"image\":{\"@id\":\"http:\/\/ipsnews.net\/business\/2020\/05\/01\/meet-eventbot-a-new-android-malware-that-steals-banking-passwords-and-two-factor-codes\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/techcrunch.com\/wp-content\/uploads\/2020\/04\/GettyImages-924145016.jpg?w=730&amp;crop=1\",\"datePublished\":\"2020-05-01T19:40:00+00:00\",\"author\":{\"@id\":\"https:\/\/ipsnews.net\/business\/#\/schema\/person\/cee3758d3201f95199de3522858ca7e2\"},\"breadcrumb\":{\"@id\":\"http:\/\/ipsnews.net\/business\/2020\/05\/01\/meet-eventbot-a-new-android-malware-that-steals-banking-passwords-and-two-factor-codes\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\/\/ipsnews.net\/business\/2020\/05\/01\/meet-eventbot-a-new-android-malware-that-steals-banking-passwords-and-two-factor-codes\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"http:\/\/ipsnews.net\/business\/2020\/05\/01\/meet-eventbot-a-new-android-malware-that-steals-banking-passwords-and-two-factor-codes\/#primaryimage\",\"url\":\"https:\/\/techcrunch.com\/wp-content\/uploads\/2020\/04\/GettyImages-924145016.jpg?w=730&amp;crop=1\",\"contentUrl\":\"https:\/\/techcrunch.com\/wp-content\/uploads\/2020\/04\/GettyImages-924145016.jpg?w=730&amp;crop=1\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\/\/ipsnews.net\/business\/2020\/05\/01\/meet-eventbot-a-new-android-malware-that-steals-banking-passwords-and-two-factor-codes\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/ipsnews.net\/business\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Meet EventBot, a new Android malware that steals banking passwords and two-factor codes\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/ipsnews.net\/business\/#website\",\"url\":\"https:\/\/ipsnews.net\/business\/\",\"name\":\"Business\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/ipsnews.net\/business\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/ipsnews.net\/business\/#\/schema\/person\/cee3758d3201f95199de3522858ca7e2\",\"name\":\"Aneesa\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/ipsnews.net\/business\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/5635ace541744f4e232d93d2fafa63d478ed1fd5c863cbc1484fc2148961368f?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/5635ace541744f4e232d93d2fafa63d478ed1fd5c863cbc1484fc2148961368f?s=96&d=mm&r=g\",\"caption\":\"Aneesa\"},\"sameAs\":[\"https:\/\/icrowdnewswire.com\/fc\"],\"url\":\"https:\/\/ipsnews.net\/business\/author\/aneesa\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Meet EventBot, a new Android malware that steals banking passwords and two-factor codes - Business","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"http:\/\/ipsnews.net\/business\/2020\/05\/01\/meet-eventbot-a-new-android-malware-that-steals-banking-passwords-and-two-factor-codes\/","og_locale":"en_US","og_type":"article","og_title":"Meet EventBot, a new Android malware that steals banking passwords and two-factor codes - Business","og_description":"Security researchers are sounding the alarm over a newly discovered&nbsp;Android&nbsp;&nbsp;malware that targets banking apps and cryptocurrency wallets. The malware, which researchers at security firm&nbsp;Cybereason&nbsp;&nbsp;recently discovered and&nbsp;called EventBot, masquerades as a legitimate Android app &mdash; like Adobe Flash or Microsoft Word for Android &mdash; which abuses Android&rsquo;s in-built accessibility features to obtain deep access to the &hellip; Continue reading Meet EventBot, a new Android malware that steals banking passwords and two-factor codes Continue Reading &rarr;","og_url":"http:\/\/ipsnews.net\/business\/2020\/05\/01\/meet-eventbot-a-new-android-malware-that-steals-banking-passwords-and-two-factor-codes\/","og_site_name":"Business","article_published_time":"2020-05-01T19:40:00+00:00","og_image":[{"url":"https:\/\/techcrunch.com\/wp-content\/uploads\/2020\/04\/GettyImages-924145016.jpg?w=730&amp;crop=1","type":"","width":"","height":""}],"author":"Aneesa","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Aneesa","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"http:\/\/ipsnews.net\/business\/2020\/05\/01\/meet-eventbot-a-new-android-malware-that-steals-banking-passwords-and-two-factor-codes\/","url":"http:\/\/ipsnews.net\/business\/2020\/05\/01\/meet-eventbot-a-new-android-malware-that-steals-banking-passwords-and-two-factor-codes\/","name":"Meet EventBot, a new Android malware that steals banking passwords and two-factor codes - Business","isPartOf":{"@id":"https:\/\/ipsnews.net\/business\/#website"},"primaryImageOfPage":{"@id":"http:\/\/ipsnews.net\/business\/2020\/05\/01\/meet-eventbot-a-new-android-malware-that-steals-banking-passwords-and-two-factor-codes\/#primaryimage"},"image":{"@id":"http:\/\/ipsnews.net\/business\/2020\/05\/01\/meet-eventbot-a-new-android-malware-that-steals-banking-passwords-and-two-factor-codes\/#primaryimage"},"thumbnailUrl":"https:\/\/techcrunch.com\/wp-content\/uploads\/2020\/04\/GettyImages-924145016.jpg?w=730&amp;crop=1","datePublished":"2020-05-01T19:40:00+00:00","author":{"@id":"https:\/\/ipsnews.net\/business\/#\/schema\/person\/cee3758d3201f95199de3522858ca7e2"},"breadcrumb":{"@id":"http:\/\/ipsnews.net\/business\/2020\/05\/01\/meet-eventbot-a-new-android-malware-that-steals-banking-passwords-and-two-factor-codes\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["http:\/\/ipsnews.net\/business\/2020\/05\/01\/meet-eventbot-a-new-android-malware-that-steals-banking-passwords-and-two-factor-codes\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"http:\/\/ipsnews.net\/business\/2020\/05\/01\/meet-eventbot-a-new-android-malware-that-steals-banking-passwords-and-two-factor-codes\/#primaryimage","url":"https:\/\/techcrunch.com\/wp-content\/uploads\/2020\/04\/GettyImages-924145016.jpg?w=730&amp;crop=1","contentUrl":"https:\/\/techcrunch.com\/wp-content\/uploads\/2020\/04\/GettyImages-924145016.jpg?w=730&amp;crop=1"},{"@type":"BreadcrumbList","@id":"http:\/\/ipsnews.net\/business\/2020\/05\/01\/meet-eventbot-a-new-android-malware-that-steals-banking-passwords-and-two-factor-codes\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/ipsnews.net\/business\/"},{"@type":"ListItem","position":2,"name":"Meet EventBot, a new Android malware that steals banking passwords and two-factor codes"}]},{"@type":"WebSite","@id":"https:\/\/ipsnews.net\/business\/#website","url":"https:\/\/ipsnews.net\/business\/","name":"Business","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/ipsnews.net\/business\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/ipsnews.net\/business\/#\/schema\/person\/cee3758d3201f95199de3522858ca7e2","name":"Aneesa","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/ipsnews.net\/business\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/5635ace541744f4e232d93d2fafa63d478ed1fd5c863cbc1484fc2148961368f?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/5635ace541744f4e232d93d2fafa63d478ed1fd5c863cbc1484fc2148961368f?s=96&d=mm&r=g","caption":"Aneesa"},"sameAs":["https:\/\/icrowdnewswire.com\/fc"],"url":"https:\/\/ipsnews.net\/business\/author\/aneesa\/"}]}},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/posts\/8682","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/comments?post=8682"}],"version-history":[{"count":1,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/posts\/8682\/revisions"}],"predecessor-version":[{"id":8683,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/posts\/8682\/revisions\/8683"}],"wp:attachment":[{"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/media?parent=8682"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/categories?post=8682"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/tags?post=8682"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}