EventBot

MITRE ATT&CK: S0478 View on attack.mitre.org

Aliases: EventBot

Malware type
trojan, credential-stealer, spyware
Family
Malware family
Operating systems
android
Related IoCs
1 (1 malicious)
Last IoC activity
2026-06-16 09:56:12
Profile updated
2026-07-07 14:06:05

Targeted industries: financial-services

Targeted regions: country_code:de country_code:fr country_code:it country_code:es country_code:gb

Context

EventBot is an Android banking trojan and information stealer that abuses Android’s accessibility service to steal data from various applications. EventBot was designed to target over 200 different banking and financial applications, the majority of which are European bank and cryptocurrency exchange applications.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to EventBot (S0478). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample eventbot.apk 2026-06-16 2

Malware & tools used

  • Symmetric Cryptography (attack-pattern)
  • Web Protocols (attack-pattern)
  • Download New Code at Runtime (attack-pattern)
  • SMS Messages (attack-pattern)
  • Match Legitimate Name or Location (attack-pattern)
  • GUI Input Capture (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Software Discovery (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Screen Capture (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Keylogging (attack-pattern)
  • Internet Connection Discovery (attack-pattern)
  • Broadcast Receivers (attack-pattern)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Apk.Eventbot (report)
  • twitter.com — 1240664876558823424 (report)
  • youtube.com — Watch (report)
  • cybereason.com — Eventbot A New Mobile Banking Trojan Is Born (report)
  • MITRE ATT&CK — S0478 (report)

External references