EventBot: what it is and how to remove it
EventBot is a malicious application that can run on Android-based devices and targets users in the US and Europe. It was first spotted in March 2020, and security researchers from Cybereason Nocturnus were analyzing the malware closely for several weeks before releasing their findings.
Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
Programs like EventBot usually arrive in groups; a free scan lists the companions that are easy to miss.
Do it yourself · free Remove EventBot yourself 5 steps, about 15 minutes, no software needed.
Start the steps
EventBot: summary
| Distribution | Like many other malicious apps designed for mobile devices, EventBot is installed via fake applications downloaded from third-party sites (such as P2P) |
|---|---|
| Name | EventBot |
| Type | Android virus, Financial Trojan |
| Release date | March 2020 |
| Primary function | Harvest sensitive financial data and device information and send it to a remote server for the attackers to abuse |
| Capabilities | Web injection Data theft from over 200 financial apps SMS grabbing 2FA bypass Keylogging |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 7 more facts
| Versions | Version 0.0.0.1, Version 0.0.0.2, Version 0.3.0.1, Version 0.4.0.1 |
|---|---|
| Detection names | No Microsoft detection name is known |
| Damage | Not recorded in the old report |
| Symptoms | An unknown program in Installed apps |
| Evidence | 5 write-ups by security sites; details still limited |
| First seen | 6 May 2020 |
| Facts checked | 7 October 2026 |
What EventBot does on an infected PC
From our report of May 2020 · not reviewed since
EventBot versions and improvements
Even though EventBot is a relatively new malware strain, several versions were already identified by security researchers, including:
Based on numerous differences between these variants, security experts quickly concluded that EventBot is still under active development:
While researchers managed to identify several peculiarities about EventBot malware itself, they could not link it with any cybercriminal gangs, all while monitoring underground forums. This is another strong hint that the virus is not yet fully released, and will be available for sale only later.
- Version 0.0.0.1 uses RC4 and Base64 Packet encryption to send out device information and other metadata within a JSON file. The action is repeated until a successful connection to C2 server is made.
- Version 0.0.0.2 loads its main module dynamically, preventing static analysis from outside sources.
- Version 0.3.0.1 includes region-based features to make the app more believable in different countries. This variant also included a function that allows malware to track PIN changes within settings.
- Version 0.4.0.1 incorporated new obfuscation techniques with the help of ProGuard. Additionally, the package name was no longer "com.example.eventbot," which makes it more difficult to detect.

From our report of May 2020 · not reviewed since
Avoid downloading apps from third-parties
Currently, there are over 2.8 million apps on Google Play and, while the IT giant Google does not always manage to keep malicious applications away, it is one of the most secure platforms to use.
Of course, security measures are applied in most other websites, although they are nowhere near as extensive as Google's. In most cases, users are keen on downloading apps from unknown sites after they see a link on various platforms, such as Facebook or YouTube.
By default, Android devices are configured not to allow apps from external sources to be installed in the first place. However, many users deliberately switch that function off, exposing their smartphones to potential risks and malware infections. Therefore, turn the security feature back on and avoid third-party sources as much as possible.
Other tips to keep your Android device secure:
- Before installing application, check for permissions it asks for, and ask yourself whether a weather app needs access to read your SMS;
- Always keep your device up to date;
- Install powerful anti-malware software that would detect online treats for you;
- Enable Google Play Protect feature.
From our report of May 2020 · not reviewed since
EventBot - dangerous financial malware designed for Android devices
EventBot is a malicious application that can run on Android-based devices and targets users in the US and Europe.
It was first spotted in March 2020, and security researchers from Cybereason Nocturnus were analyzing the malware closely for several weeks before releasing their findings.
As it turns out, EventBot is a Trojan that abuses accessibility feature within Android OS in order to steal banking and other information from over 200 different financial apps. Malware is also capable of bypassing two-factor authentication, reading data from crypto-wallets, as well as stealing SMS message contents.
Since EventBot virus is operating in the background, users who are not protecting their devices with security solutions might never know that they are infected in the first place. In the meantime, the malicious app can gather sensitive data and deliver it to cybercriminals.
Victims can suffer significant monetary losses, have their credit score corrupted, loans are taken out in their names, and suffer from identity theft. While EventBot is still under active development, it is malware that Android users should be very scared of.
Smartphones are now standalone devices greatly surpassing desktop machines when it comes to volume. According to statistics portals, there are more than 14 billion mobile devices currently in circulation, , so there is no doubt that threat actors are willing to benefit from this saturated market.
This can also be noted with an increasing amount of malware that is being produced for portable devices, especially Android OS-based ones. The malware was created to steal from victims and benefit cybercriminals - we will try to explain how to prevent its infiltration and how to remove EventBot virus for good to avoid extensive data compromise.
Just like many other Android virus members, EventBot makes its way to users' devices via applications downloaded from insecure third-party sources. While some apps might be unheard of, it is not uncommon for malware to be disguised as a well-known application. Researchers also managed to trace several legitimate application icons that were used to disguise EventBot malware inside.
Before the installation is complete, EventBot asks for several permissions within the Android device, some of which include:
Knowing about EventBot capabilities and purpose, these permissions make much sense. Nonetheless, many users do not pay close attention to permissions and simply allow them all during the installation of the fake app, as they believe it can be trusted (e.g., Adobe Flash Player, MS Word, etc.).
Once established, EventBot Trojan asks for accessibility service access. These are typically used to help users with disabilities to help them perform actions on their mobile devices they would normally not be able to, such as writing, performing gestures, and other functions. With this permission, EventBot will be able to operate as a keylogger, recording all inputs and screen presses from that point.
As soon as it establishes itself, EventBot downloads a configuration file for 200 different financial apps, which include Santander, CapitalOne, HSBC, UniCredit, Revolut, TransferWise, Coinbase, Paypal Business, and many more. This allows the malware to gather sensitive information, such as keystrokes, passwords, transactions, from these apps and send it off to a remote server (data is encrypted with various different ciphers, depending on the version).
When it comes to EventBot removal, only a reputable anti-malware software can help you. When it comes to its detection, you might not notice the malware operating the background, although excessive battery usage is one of the main indicators of the infection. Additionally, we would like to recommend using to optimize and keep your Android device clean.
- install other packages;
- create windows that are shown on top of other apps;
- allow running in the background;
- allow reading SMS contents;
- access information about network;
- allow the app to start with each device launch, etc.


From our report of May 2020 · not reviewed since
More from our earlier report on EventBot
- To eliminate malware from Android device a full scan with reputable anti-malware software should be performed
- EventBot is in constant development, as seen with the botnetID string above, which shows consecutive numbering across versions.
- This example is from a later version of EventBot, and in other versions the naming convention is very similar, with bot IDs such as word100, word101, word102, and test2005, test2006 etc.
How to remove EventBot
A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.
Step 1: Delete scheduled tasks that bring it back
Programs like EventBot add a scheduled task so they return after an uninstall or reopen a page at every sign-in. Start Task Scheduler, open Task Scheduler Library and sort by Last Run Time to see what ran recently.
On the Actions tab, a program in a user folder, a script or a web address is a warning sign; right-click such a task and choose Delete.
Tasks with names copying Google, Edge or Windows updaters but pointing to an odd folder are typical. The tool looks the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 2: Remove it from startup
Press Ctrl + Shift + Esc to open Task Manager and select Startup apps (Windows 11) or the Startup tab (Windows 10). Disable entries you do not recognise, especially ones with no publisher or with a name that copies a Windows component.
Right-click an entry and choose Open file location to see where it runs from: programs in
%AppData%or%Temp%deserve a closer look. Some entries are not listed there but in the registry Run keys, which the procedure below shows how to check.Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 3: Delete the folders left behind
Uninstalling often leaves the program's folders, and some threats reinstall themselves from them.
Press Windows + R, type
%LocalAppData%and press Enter, then do the same for%AppData%and %ProgramData%, and look for folders named after EventBot, its publisher or created on the day the problem started. Delete those folders, and check C:\Program Files and C:\Program Files (x86) too.If Windows says a file is in use, end it in Task Manager or delete the folder after a restart in Safe Mode. The folders are the same in Windows 11 and Windows 10.
Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 4: Scan the PC, then run the offline scan
A scan finds the parts of EventBot that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.
Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.
It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Change passwords from another device and sign out other sessions
EventBot can copy saved passwords, cookies and session tokens and send them out in seconds, so cleaning the PC does not undo the theft.
Change your passwords on a device that was never infected, starting with the e-mail account, since every other reset goes through it. On each account, end all other sessions and check the recovery e-mail, phone number and forwarding rules.
Then turn on two-step verification. Sign in on the Windows 11 or Windows 10 PC again only after the offline scan is clean.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
From our report of May 2020 · not reviewed since
Eliminate EventBot malware to protect your finances and privacy
As previously mentioned, EventBot virus might not emit any symptoms, just like many other Trojans do, as they are programmed to operate stealthily.
This outlines how important it is to protect mobile devices with security software, and that malware might operate silently in the background for a prolonged time without being noticed. Nonetheless, since the virus actively communicates with a remote server, sends packet information, and performs a variety of other actions, the phone or tablet might suffer from battery drain.
For EventBot removal, employ a powerful anti-malware software and perform a full system scan. Please be aware that not all mobile security tools are effective, as was confirmed by an in depended testing lab AV-Comparatives. Thus, make sure you pick a reliable anti-malware first.
Once you remove EventBot from your system, you should also clear your web browser data and immediately change your passwords for all the apps/accounts. Additionally, you should monitor your online banking to ensure that no illegal transactions are performed. If that is the case, contact your bank immediately and block the account.
After removal: passwords, accounts and prevention
Your passwords after EventBot
Removing EventBot does not undo what it may already have sent out while the PC showed eventBot in the list of installed apps.
Treat saved browser passwords and logged-in sessions on this PC as known to the attacker.
From another device, change the e-mail password first and end all its sessions. Then do the same for the bank, PayPal, Microsoft, Google and Apple accounts. Stolen session cookies keep working after a password change until you sign out everywhere.
Move crypto to a new wallet created on a clean device. A step-by-step order for every kind of account is in our guide to account security after an infection.
Stream videos without limitations, no matter where you are
There are multiple parties that could find out almost anything about you by checking your online activity.
While this is highly unlikely, advertisers and tech companies are constantly tracking you online. The first step to privacy should be a secure browser that focuses on tracker reduction to a minimum.
Even if you employ a secure browser, you will not be able to access websites that are restricted due to local government laws or other reasons. In other words, you may not be able to stream Disney+ or US-based Netflix in some countries. To bypass these restrictions, you can employ a powerful VPN, which provides dedicated servers for torrenting and streaming, not slowing you down in the process.
Data backups are important - recover your lost files
Ransomware is one of the biggest threats to personal data.
Once it is executed on a machine, it launches a sophisticated encryption algorithm that locks all your files, although it does not destroy them. The most common misconception is that anti-malware software can return files to their previous states. This is not true, however, and data remains locked after the malicious payload is deleted.
While regular data backups are the only secure method to recover your files after a ransomware attack, tools such as can also be effective and restore at least some of your lost data.
Questions about EventBot
Is EventBot a virus?
Most programs that appear the way EventBot did are not viruses in the strict sense. They are potentially unwanted programs:
- real software that arrives bundled with other downloads and then shows offers
- changes browser settings
- starts with Windows
Some are harmless, some are annoying and a few carry adware. What makes it worth removing is that you did not choose it.
Uninstall it from Installed apps and check the startup list and the browsers for anything added the same day. If it refuses to uninstall or returns after a restart, treat it as more serious and run a Microsoft Defender offline scan.
EventBot came back after I uninstalled it. Why?
Something else is reinstalling it. Common causes are a second program from the same publisher, a scheduled task that downloads it again, or a browser extension that keeps prompting for it. Sort Installed apps by install date and uninstall each entry from the same day that you did not choose.
Then open Task Scheduler and look in the Task Scheduler Library for tasks with updater-style names that you do not recognise. Check Startup apps in Task Manager too. If EventBot still returns, start Windows in Safe Mode, uninstall it there and run a Microsoft Defender offline scan, which looks for loaders that ordinary scans can miss.
Should I check my other computers too?
Yes, it takes little time and removes doubt. EventBot itself usually stays on one PC, but the download that carried it may have been copied to other computers, shared drives may hold the same installer, and an attacker who had access could have tried saved passwords on other devices.
Run a full scan on every Windows PC in the home or office, check shared folders for the original download, and change Wi-Fi and router passwords if they were stored on the infected machine.
How do I know if my PC has EventBot?
Often you do not, which is the point of a trojan. Possible signs are an antivirus alert naming EventBot or a generic trojan detection, unknown programs or scheduled tasks, processes with random names in Task Manager, browser extensions you did not add, security settings turned off, slower performance, or account alerts about logins from unknown places.
The reliable check is a full scan followed by Microsoft Defender's offline scan. If you recently ran a crack, a fake installer or a command a website told you to paste, scan even without symptoms.
Should I report EventBot?
Report it if you lost money, if accounts were taken over, if you are a business, or if the trojan came through a scam call. A police or national cybercrime report gives you a reference number for your bank and insurer and helps link cases.
You do not need to report a trojan that antivirus blocked before it ran. Before reporting, write down the dates, the detection name, file names and any messages or transactions linked to the attack; screenshots of antivirus alerts are useful evidence. The country list is in the report section above.
I found AnyDesk or ScreenConnect that I did not install. Is that EventBot?
Not necessarily EventBot, but it is a warning sign. These are legitimate remote support tools, and criminals use them as ready-made backdoors, especially after tech support scams or fake invoice calls.
If you did not install it and no one you trust set it up, uninstall it, change passwords from a clean device and check your bank account. If someone connected to your PC through it, follow the steps for remote access trojans and consider a Windows reset. Installed apps sorted by date shows when it appeared.
My antivirus was on. How did a trojan get past it?
Antivirus programs see a file only when it is written or run, and criminals test each new build against popular scanners before release. Detection catches up within hours or days, which is often after the first victims ran it.
Archives with passwords, installers that fetch the malware later, and scripts run through PowerShell make the job harder. That is why behaviour such as downloading cracks or pasting commands matters more than any setting. Keep Windows and Defender updated, and turn on Reputation-based protection in App & browser control.
Is it safe to do online banking after seeing eventBot in the list of installed apps?
Not on that PC until it is clean. A program that produces eventBot in the list of installed apps runs with your rights and could read what you type or what the browser shows. Use a phone or another computer for banking and for changing passwords.
When the offline scan of the affected PC is clean and nothing suspicious starts with Windows any more, you can go back to using it. Check your bank statements for the past weeks either way, and call the bank if anything looks unfamiliar; banks can block cards and reset access quickly.
Is EventBot a known trojan?
Not as a documented family, at least not yet. What is known is the visible sign, eventBot in the list of installed apps, which matches a hidden program working for someone else.
New threats are often seen by victims weeks before researchers publish anything about them. Treat EventBot as you would any trojan:
- remove what starts it
- run an offline scan
- change passwords from another device
If a scan reports a detection name, keep it; it usually reveals the family and whether it is known to download other malware. We update this guide when an analysis appears.
Will Fortect remove EventBot?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For EventBot, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- Cybereason: EventBot: A New Mobile Banking Trojan is Born (read October 7, 2026)
- Statista: Forecast number of mobile devices worldwide from 2019 to 2023 (in billions)* (read October 7, 2026)
- Zimperium: One-third of all malware is now mobile (read October 7, 2026)
- Statista: Number of available applications in the Google Play Store from December 2009 to March 2020 (read October 7, 2026)
- FTC: How to recognize, remove and avoid malware (read October 7, 2026)