CERT-In Says Mobile Banking Android Malware 'EventBot' Horsing Around in Cyberspace

A Trojan is a virus or malware that cheats a victim to stealthily attack its computer or phone-operating system.

Advertisement
By Press Trust of India | Updated: 15 May 2020 00:50 IST
Highlights
  • CERT-In is the national technology arm to combat cyber attacks
  • The cyber security agency has suggested certain counter-measures
  • It also asked users to avoid using unsecured, unknown Wi-Fi networks

The cyber security agency has suggested certain counter-measures to check the virus in Android phones

A mobile banking malware called "EventBot", which steals personal financial information, may affect Android phone users in India, the federal cyber-security agency has said in a latest advisory.

The CERT-In has issued a caution, saying the Trojan virus may "masquerade as a legitimate application such as Microsoft Word, Adobe Flash, and others using third-party application downloading sites to infiltrate into victim device".

A Trojan is a virus or malware that cheats a victim to stealthily attack its computer or phone-operating system.

Advertisement

"It has been observed that a new Android mobile malware named EventBot is spreading.

Advertisement

"It is a mobile-banking Trojan and info-stealer that abuses Android''s in-built accessibility features to steal user data from financial applications, read user SMS messages and intercept SMS messages, allowing malware to bypass two-factor authentication," the CERT-In advisory said.

The Computer Emergency Response Team of India (CERT-In) is the national technology arm to combat cyber attacks and guard the Indian cyber space.

Advertisement

"EventBot", it said, targets over 200 different financial applications, including banking applications, money-transfer services, and cryptocurrency wallets, or financial applications based in the US and Europe region at the moment but some of their services may affect Indian users as well.

The virus "largely targets financial applications like Paypal Business, Revolut, Barclays, UniCredit, CapitalOne UK, HSBC UK, TransferWise, Coinbase, paysafecard etc.," the CERT-In said.

Advertisement

The agency said while "EventBot" has not been "seen" on Google Play Store till now, it can "masquerade" as a genuine mobile phone application.

"Once installed on victim''s Android device, it asks permissions such as controlling system alerts, reading external storage content, installing additional packages, accessing Internet, whitelisting it to ignore battery optimisation, prevent processor from sleeping or dimming the screen, auto-initiate upon reboot, receive and read SMS messages, and continue running and accessing data in the background," the advisory explained.

The virus further prompts the users to give access to their device accessibility services.
"Also, it can retrieve notifications about other installed applications and read contents of other applications.

"Over the time, it can also read Lock Screen and in-app PIN that can give attacker more privileged access over victim device," the advisory said.

The cyber-security agency has suggested certain counter-measures to check the virus infection into Android phones:

"Do not download and install applications from untrusted sources like unknown websites and links on unscrupulous messages; install updated anti-virus solution; prior to downloading or installing apps (even from Google Play Store), always review the app details, number of downloads, user reviews, comments, and the ''additional information'' section.

Exercise caution while visiting trusted/un-trusted sites for clicking links; install Android updates and patches as and when available; users are advised to use device encryption or encrypting external SD card feature available with most of the Android operating system."

It also asked users to avoid using unsecured, unknown Wi-Fi networks and for prior confirming of a banking/financial app from the source organisation.

"Make sure you have a strong artificial intelligence (AI) powered mobile antivirus installed to detect and block this kind of tricky malware if it ever makes its way onto your system," the advisory states.


Which is the bestselling Vivo smartphone in India? Why has Vivo not been making premium phones? We interviewed Vivo's director of brand strategy Nipun Marya to find out, and to talk about the company's strategy in India going forward. We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Apple to Reportedly Launch Low-Cost MacBook in 'Playful Colors' in March
  2. Vivo X300 FE Reportedly Bags IMDA and TUV Certifications Ahead of Launch
  3. Samsung Galaxy S26+ Reportedly Listed for Sale Online Ahead of Launch
  4. Anthropic's First Indian Office in Bengaluru Is Now Open
  5. Lava Bold N2 Will Be Launched in India on This Date: See Expected Specs
  6. Oppo K14x 5G With 6,500mAh Battery Goes on Sale in India: See Price, Offers
  7. Deals on iPhone 17, Google Pixel 10 and More During Flipkart Sale
  8. AI Impact Summit: From Registration to Schedule, All You Need to Know
  9. Samsung Galaxy A27 5G Lands on IMEI Database, Could Launch Soon
  10. Tecno Spark 50 4G Launch Timeline, Design, Colourways, Key Features Leaked
  1. X Building Smart 'Cashtags' to Let Users Check Cryptocurrency Prices in Real-Time
  2. Samsung Galaxy A27 5G Listing on IMEI Database Suggests a Galaxy A26 Successor Is on the Way
  3. Anthropic Inaugurates First Indian Office in Bengaluru, Starts Hiring Local Talent
  4. Apple Tipped to Adopt Samsung's Privacy Display Technology for MacBook Models by 2029
  5. Oppo Find X10 Series Tipped to Launch in H2 2026 With Built-In Magnets for Wireless Charging
  6. AMD and TCS to Co-Develop Helios AI Data Centre Architecture, Deliver 200MW Data Centre Blueprint
  7. Tecno Spark 50 4G Tipped to Launch Globally Soon; Design, Colourways, Key Features Leaked
  8. Lava Bold N2 India Launch Date Revealed; Will Be Exclusively Available via Amazon
  9. Government Green Lights Rs. 10,000 Crore Fund of Funds 2.0 Under the Startup India Mission
  10. Samsung’s 'Wide' Galaxy Z Fold Design Revealed via Leaked One UI 9 Animations
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.