logo

AbereBot Returns As Escobar

ID: bf4858ee-cdea-5125-aaa9-325e6d780c2f

STIX ID: report--bf4858ee-cdea-5125-aaa9-325e6d780c2f

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-11-17

Date Updated: 2026-07-16

...
...

**Escobar (Aberebot variant)**: Technical analysis of an Android banking Trojan disguised as a McAfee app (package com.escobar.pablo) describing abused permissions, capabilities to steal contacts, SMS, call logs, Google Authenticator codes, media and location, remote control via VNC, available commands, MITRE ATT&CK mappings, and file hashes (SHA256/SHA1/MD5) as indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.