EventBot
MITRE ATT&CK: S0478 View on attack.mitre.org
Aliases: EventBot
- Malware type
- trojan, credential-stealer, spyware
- Family
- Malware family
- Operating systems
- android
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-06-16 09:56:12
- Profile updated
- 2026-07-07 14:06:05
Targeted industries: financial-services
Targeted regions: country_code:de country_code:fr country_code:it country_code:es country_code:gb
Context
EventBot is an Android banking trojan and information stealer that abuses Android’s accessibility service to steal data from various applications. EventBot was designed to target over 200 different banking and financial applications, the majority of which are European bank and cryptocurrency exchange applications.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to EventBot (S0478). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | eventbot.apk | 2026-06-16 | 2 |
Malware & tools used
- Symmetric Cryptography (attack-pattern)
- Web Protocols (attack-pattern)
- Download New Code at Runtime (attack-pattern)
- SMS Messages (attack-pattern)
- Match Legitimate Name or Location (attack-pattern)
- GUI Input Capture (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Software Discovery (attack-pattern)
- System Information Discovery (attack-pattern)
- Screen Capture (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Keylogging (attack-pattern)
- Internet Connection Discovery (attack-pattern)
- Broadcast Receivers (attack-pattern)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Apk.Eventbot (report)
- twitter.com — 1240664876558823424 (report)
- youtube.com — Watch (report)
- cybereason.com — Eventbot A New Mobile Banking Trojan Is Born (report)
- MITRE ATT&CK — S0478 (report)