High
A new mobile banking Trojan Eventbot is currently targeting financial applications in Europe. Eventbot uses a completely new code structure, which is completely different from the currently known banking Trojans. The Eventbot Trojan tricks users into installing it by impersonating normal application icons. After it runs, it will upgrade and update by impersonating, hiding its icon to protect itself. The Eventbot Trojan monitors the user’s mobile phone through the Accessibility Service function, with more than 50 malicious functions. After running, it will issue instructions through the server to control the user’s mobile phone, such as: get and upload the user’s mobile phone text message, get and upload the user’s mobile phone configuration information, get and upload the user’s mobile phone’s installed application, and perform user’s mobile phone browser Inject, launch the specified APP of the user’s mobile phone, delete the specified application, update malicious plug-ins and other malicious behaviors.
Issue instructions through the server
Currently it affects a dozen banking apps in Britain, Germany, Italy, Spain and other countries, affecting a total of 234 financial applications.
MD5
SHA-256
URL