Overview
Escobar was first seen on the 3rd of March by the security researchers MalwareHunterTeam. Escobar is based on the Aberebot Android banking trojan. However, it has been improved and is now advertised for rental, with new features added, which include the functionality to steal Google Authenticator multifactor authentication (MFA) codes.
Impact
The application gains access to different areas of an Android mobile device, including being able to capture sound and images, send SMS, inject URLs, and read Google Authenticator codes. Escobar has also been seen to initiate a VNC Viewer process which can be utilised to control user devices. VNC Viewer has been utilised as this will allow the threat actor to subvert access to any e-banking present on the device.
Impacted Devices
All Android versions.
Vulnerability Detection
Recommendation: to monitor Mobile/Wi-Fi usage of applications.
Unexpected permissions sought, such as ‘Take Photo’, ‘Send SMS’, ‘Microphone’, which are used to record users.
Containment, Mitigations & Remediations
For now, the recommendation is to avoid installation of APK’s outside of Google Play, enable Google Play Protect and the use of a mobile security tool.
If detected, researchers recommend:
– Disable Wi-Fi/Mobile data and remove SIM card – as in some cases, the malware can re-enable the Mobile Data.
– Perform a factory reset.
– Remove the application in case a factory reset is not possible.
– Take a backup of personal media Files (excluding mobile applications) and perform a device reset.












