Escobar
MITRE ATT&CK: S1092 View on attack.mitre.org
Aliases: Escobar
- First seen
- 2021-03-01 00:00:00
- Malware type
- trojan, credential-stealer
- Family
- Malware family
- Operating systems
- android
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-08-14 14:26:23
- Profile updated
- 2026-07-07 14:03:13
Targeted industries: financial-services
Targeted regions: country_code:es country_code:mx country_code:br
Context
Escobar is an Android banking trojan, first detected in March 2021, believed to be a new variant of AbereBot.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to Escobar (S1092). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | escobar.apk | 2026-08-14 | 2 |
Malware & tools used
- SMS Messages (attack-pattern)
- Video Capture (attack-pattern)
- Call Control (attack-pattern)
- Lockscreen Bypass (attack-pattern)
- Location Tracking (attack-pattern)
- Stored Application Data (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Call Log (attack-pattern)
- Access Notifications (attack-pattern)
- SMS Control (attack-pattern)
- Remote Access Software (attack-pattern)
- Data from Local System (attack-pattern)
- Keylogging (attack-pattern)
- Uninstall Malicious Application (attack-pattern)
- Audio Capture (attack-pattern)
- GUI Input Capture (attack-pattern)
Reports & references
- bleepingcomputer.com — Android Malware Escobar Steals Your Google Authenticator Mfa Codes (report)
- MITRE ATT&CK — S1092 (report)