New Android banking trojan is able to bypass two-factor authentication

Customers using HSBC, Paypal, Barclays, Revolut, and Transferwise are all vulnerable to Eventbot, researchers claim

A new mobile-based trojan has been discovered that's capable of compromising Android’s accessibility features in order to steal user data from banking applications and read user’s SMS messages, allowing the malware to bypass two-factor authentication.

Named Eventbot, the trojan was discovered by a group of cyber security experts from Cybereason Nocturnus, who found it targeting financial banking applications in the United States and Europe, including the UK.

Advertisement - Article continues below

Over 200 different financial applications have been susceptible to the Eventbot’s attacks, including banking, money transfer services, and crypto-currency wallets operated by organisations such as HSBC, Santander, Barclays, Paypal Business, Revolut, UniCredit, CapitalOne UK, and TransferWise.

Daniel Frank, Lior Rochberger, Yaron Rimmer, and Assaf Dahan of Cybereason Nocturnus all contributed to the research into the trojan, details of which have been published on the cyber security group’s blog.

“EventBot is particularly interesting because it is in such early stages,” they wrote. “This brand new malware has real potential to become the next big mobile malware, as it is under constant iterative improvements, abuses a critical operating system feature, and targets financial applications.”

What's particularly concerning is that this trojan is also capable of reading a user's SMS messages, and therefore any security codes sent to a device as part of a two-factor authentication setup.

Advertisement - Article continues below

The cyber security experts advise Android users to take precautionary measures such as updating their mobile device to the latest software, which should originate from legitimate sources, keeping Google Play Protect on, and using mobile threat detection solutions for enhanced security.

Related Resource

Decade of the RATs - remote access trojans

Cross-platform APT espionage attacks targeting Linux, Windows and Android

Download now

The team from Cybereason Nocturnus also warned against downloading mobile apps from unofficial or unauthorized sources and recommended applying critical thinking when giving a certain app the permissions it requested.

Advertisement - Article continues below

In the blog post, they warned that “once this malware has successfully installed, it will collect personal data, passwords, keystrokes, banking information, and more”.

“60% of devices containing or accessing enterprise data are mobile. Giving an attacker access to a mobile device can have severe business consequences, especially if the end user is using their mobile device to discuss sensitive business topics or access enterprise financial information. This can result in brand degradation, loss of individual reputation, or loss of consumer trust.”

Last week, it was reported that threat groups are increasingly relying on trojanised apps posing as legitimate versions in order to spread surveillanceware.

Featured Resources

The case for a marketing content hub

Transform your digital marketing to deliver customer expectations

Download now

Fast, flexible and compliant e-signatures for global businesses

Be at the forefront of digital transformation with electronic signatures

Download now

Why CEOS should care about the move to SAP S/4HANA

And how they can accelerate business value

Download now

IT faces new security challenges in the wake of COVID-19

Beat the crisis by learning how to secure your network

Download now



Evasive malware threats doubled in 2019

24 Mar 2020

Best free malware removal tools 2019

2 Mar 2020

Best antivirus for Windows 10

3 Sep 2019

Most Popular

Microsoft Windows

Microsoft warns users not to install Windows 10's May update

28 May 2020
data breaches

EasyJet faces class-action lawsuit over data breach

26 May 2020
cyber security

Microsoft bans Trend Micro driver from Windows 10 for "cheating" hardware tests

27 May 2020