Escobar is an Android banking trojan identified as a variant of Aberebot that expanded beyond financial credential theft into broader mobile surveillance and device takeover functions. It has been observed masquerading as a legitimate security application and is associated with phishing-overlay theft of login credentials. Escobar targets Android devices and abuses numerous dangerous permissions to harvest sensitive data from infected phones.
Its capabilities include theft of SMS messages, contacts, call logs, notification content, location data, media files, and one-time codes such as Google Authenticator values. Reported functionality also includes keylogging, audio recording, camera capture, remote screen control through VNC-style interaction, sending SMS messages without user awareness, placing phone calls, injecting web content, uninstalling applications, and self-deletion on operator command. These features support both banking fraud and broader post-compromise surveillance.
Escobar has been advertised in cybercrime forums and linked to the criminal ecosystem around Aberebot, which has targeted customers of numerous banks and financial institutions across multiple countries. Distribution has been assessed as occurring outside the official Android app store, with the malware relying on malicious application delivery and masquerading to induce installation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan variant masquerading as McAfee that steals credentials via phishing overlays and exfiltrates contacts, SMS, incoming SMS, call logs, key logs, media files, device location, and Google Authenticator codes. It can record audio, take photos, send SMS, inject URLs, monitor notifications, remotely control the device screen via VNC, and execute commands from a C2 server, including self-deletion and app uninstall actions.
Android malware that steals sensitive information including Google Authenticator codes.
Android malware that steals sensitive information including Google Authenticator codes.
Android malware that steals sensitive information including authenticator codes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.