EventBot is an Android banking trojan focused on financial fraud and credential theft. It is known for impersonating legitimate mobile applications through the use of trusted-looking icons, then abusing Android accessibility features and overlay-style prompts to harvest sensitive information from victims. The malware can display popups over running applications, capture user input such as the device screen PIN through accessibility abuse, and intercept SMS messages, enabling theft of one-time passcodes and other authentication data commonly used in banking workflows.
On infected devices, EventBot performs host profiling and reconnaissance by collecting installed application lists, device network information, and system details including operating system version, device vendor, and active screen-lock type. It communicates with command-and-control infrastructure over HTTP, allowing operators to manage infections and receive stolen data. EventBot also establishes persistence by registering for Android boot events so it can automatically start after device reboot.
EventBot is widely tracked as part of the Android mobile banking malware ecosystem and is frequently discussed alongside other financially motivated Android banking trojans such as Exobot, Cerberus, Alien, BlackRock, and TeaBot. Its combination of accessibility abuse, SMS interception, deceptive application presentation, and application-aware targeting makes it a notable example of modern Android banking malware aimed at account takeover and financial theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
A malicious application could create an application overlay window on top of a running legitimate application.
TeaBot, during its first communications with the C2, sends the list of installed apps to verify if the infected devices had one or more targeted apps already installed. When TeaBot found one of them, it downloads the specific payload to perform overlay attacks and starts tracking all the activity performed by the user on the targeted app.
A malicious application could create an application overlay window on top of a running legitimate application.
TeaBot, during its first communications with the C2, sends the list of installed apps to verify if the infected devices had one or more targeted apps already installed. When TeaBot found one of them, it downloads the specific payload to perform overlay attacks and starts tracking all the activity performed by the user on the targeted app.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan that displays phishing popups over active applications to capture sensitive data.
Mobile banking trojan that collects installed application lists from infected devices.
Mobile banking trojan that abuses Android accessibility services to capture sensitive user input such as PINs.
Android banking trojan that persists by auto-starting after device boot via broadcast intent registration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.