Security News > 2020 > May > Android trojan EventBot abuses accessibility services to clear out bank accounts – fortunately, it's 'in preview'

Android trojan EventBot abuses accessibility services to clear out bank accounts – fortunately, it's 'in preview'
2020-05-01 09:00

Researchers have analysed a new strain of Android malware that does not yet exist in the wild.

EventBot asks the user for permission to use accessibility services, a powerful feature since these services require extensive permissions in order to work, including acting as a keylogger, for example, and running in the background.

EventBot also requires Android permissions including reading internal storage, reading and sending SMS messages, launching automatically after system boot, showing windows on top of other apps, and requesting to install additional packages.

Would EventBot have any chance of getting past Google's malware checks?

Despite the existence of EventBot and other mobile malware, is it not true that mobile devices are still more secure than desktop PCs, which are more open and allow users more freedom in installing apps from anywhere? "The attack surface is broader with desktop," Dahan told us, "But the world is shifting fast towards mobile. Banking trojans were really big on desktop, today they have to have a mobile component. Today most banks have two-factor authentication with a code either generated or sent to the mobile phone. Threat actors have to adapt and switch to mobile."


News URL

https://go.theregister.co.uk/feed/www.theregister.co.uk/2020/05/01/eventbot_malware_abuses_android_accessibility/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Android 4 0 17 2 0 19