New Android banking trojan is able to bypass two-factor authentication

Customers using HSBC, Paypal, Barclays, Revolut, and Transferwise are all vulnerable to Eventbot, researchers claim

A new mobile-based trojan has been discovered that's capable of compromising Android’s accessibility features in order to steal user data from banking applications and read user’s SMS messages, allowing the malware to bypass two-factor authentication.

Named Eventbot, the trojan was discovered by a group of cyber security experts from Cybereason Nocturnus, who found it targeting financial banking applications in the United States and Europe, including the UK.

Advertisement - Article continues below

Over 200 different financial applications have been susceptible to the Eventbot’s attacks, including banking, money transfer services, and crypto-currency wallets operated by organisations such as HSBC, Santander, Barclays, Paypal Business, Revolut, UniCredit, CapitalOne UK, and TransferWise.

Daniel Frank, Lior Rochberger, Yaron Rimmer, and Assaf Dahan of Cybereason Nocturnus all contributed to the research into the trojan, details of which have been published on the cyber security group’s blog.

“EventBot is particularly interesting because it is in such early stages,” they wrote. “This brand new malware has real potential to become the next big mobile malware, as it is under constant iterative improvements, abuses a critical operating system feature, and targets financial applications.”

What's particularly concerning is that this trojan is also capable of reading a user's SMS messages, and therefore any security codes sent to a device as part of a two-factor authentication setup.

Advertisement
Advertisement - Article continues below

The cyber security experts advise Android users to take precautionary measures such as updating their mobile device to the latest software, which should originate from legitimate sources, keeping Google Play Protect on, and using mobile threat detection solutions for enhanced security.

Related Resource

Decade of the RATs - remote access trojans

Cross-platform APT espionage attacks targeting Linux, Windows and Android

Download now

The team from Cybereason Nocturnus also warned against downloading mobile apps from unofficial or unauthorized sources and recommended applying critical thinking when giving a certain app the permissions it requested.

Advertisement - Article continues below

In the blog post, they warned that “once this malware has successfully installed, it will collect personal data, passwords, keystrokes, banking information, and more”.

“60% of devices containing or accessing enterprise data are mobile. Giving an attacker access to a mobile device can have severe business consequences, especially if the end user is using their mobile device to discuss sensitive business topics or access enterprise financial information. This can result in brand degradation, loss of individual reputation, or loss of consumer trust.”

Last week, it was reported that threat groups are increasingly relying on trojanised apps posing as legitimate versions in order to spread surveillanceware.

Featured Resources

Staying ahead of the game in the world of data

Create successful marketing campaigns by understanding your customers better

Download now

Remote working 2020: Advantages and challenges

Discover how to overcome remote working challenges

Download now

Keep your data available with snapshot technology

Synology’s solution to your data protection problem

Download now

After the lockdown - reinventing the way your business works

Your guide to ensuring business continuity, no matter the crisis

Download now
Advertisement

Recommended

Malware attacks using machine identities doubled in 2019
cyber security

Malware attacks using machine identities doubled in 2019

4 Aug 2020
Over two dozen Android apps found stealing user data
Google Android

Over two dozen Android apps found stealing user data

7 Jul 2020
Best antivirus for Windows 10
antivirus

Best antivirus for Windows 10

30 Jun 2020
Searching for a new job? That LinkedIn job offer may be fake
hacking

Searching for a new job? That LinkedIn job offer may be fake

19 Jun 2020

Most Popular

How to find RAM speed, size and type
Laptops

How to find RAM speed, size and type

3 Aug 2020
How to use Chromecast without Wi-Fi
Mobile

How to use Chromecast without Wi-Fi

4 Aug 2020
How do you build a great customer experience?
Sponsored

How do you build a great customer experience?

20 Jul 2020