LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S1092: Escobar

Escobar is an Android banking trojan, first detected in March 2021, believed to be a new variant of AbereBot.[1]

MobileS1092MalwareObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Escobar matters because it is an Android banking trojan associated in ATT&CK with credential and data collection behaviors on mobile devices, including keylogging, GUI input capture, notification access, SMS and call data access, location tracking, audio/video capture, and remote access software. For leaders, the practical issue is not just one malware name: it is whether mobile devices used for banking, workforce authentication, communications, or executive activity are governed and monitored well enough to spot risky permissions and sensitive-data access.

Executive priority

Treat this as a mobile identity and fraud-readiness concern. The supplied ATT&CK context links Escobar to behaviors that can expose credentials, one-time codes, SMS messages, call logs, local files, and device location on Android. Security leaders should ask whether managed and unmanaged Android devices have enforceable app controls, permission visibility, incident response procedures for compromised phones, and audit evidence showing how mobile MFA and sensitive business communications are protected.

Technical view

Escobar is listed as Android malware, described by MITRE as a banking trojan first detected in March 2021 and believed to be a variant of AbereBot. No official ATT&CK detection text is provided, so SOC and IR teams should validate coverage behaviorally against the linked techniques: stored application data access, keylogging, GUI input capture, file and directory discovery, audio/video capture, location tracking, lockscreen bypass context, notification access, local data collection, SMS and call control, uninstall behavior, call log and SMS collection, and remote access software use. Prioritize review of Android permissions and events involving accessibility services, notification access, SMS/call capabilities, microphone/camera/location access, suspicious app install or uninstall activity, and unexpected remote access applications.

Likely telemetry

  • Android MDM/EMM inventory for installed applications, package names, install source, version, and uninstall events
  • Application permission state, including SMS, call, notification, accessibility, microphone, camera, location, and storage-related permissions
  • Android security and device posture data, including root/jailbreak indicators where available
  • Mobile threat defense or endpoint telemetry for suspicious overlays, keyboard behavior, accessibility abuse, and remote control activity
  • Notification, SMS, call log, and call-control permission usage where collection is legally and technically available

Detection direction

  • Because MITRE provides no official detection guidance for this object, validate detections against the related ATT&CK behaviors rather than the malware name alone.
  • Tune for high-risk permission combinations on Android, especially apps requesting accessibility plus notification, SMS, call, storage, microphone, camera, or location capabilities without a clear business justification.
  • Look for user-facing deception patterns consistent with keylogging or GUI input capture, while accounting for legitimate keyboards, accessibility tools, banking apps, and enterprise support tools as false-positive sources.
  • Review unexpected remote access software on mobile devices, especially when paired with sensitive permissions or banking/authentication use cases.
  • Correlate mobile alerts with identity events such as failed logins, unusual MFA prompts, password resets, or one-time-code use; do not assume mobile telemetry alone will prove compromise.

Mitigation priorities

  • Start with mobile asset governance: know which Android devices are allowed to access business systems and whether they are managed.
  • Enforce app installation and permission controls for devices that access sensitive applications, prioritizing restrictions around accessibility, notification, SMS, call, storage, microphone, camera, and location permissions.
  • Reduce dependence on easily intercepted mobile-delivered secrets where feasible, especially for high-risk users and financial or administrative workflows.
  • Maintain mobile incident response playbooks covering device isolation, evidence preservation, account protection, MFA reset, and review of SMS/call/notification exposure.
  • Provide user guidance focused on suspicious permission prompts, third-party keyboards, overlays, remote access apps, and unexpected requests to make an app the default SMS or phone handler.
Additional notes and limits

The decision value is in the relationship set: Escobar is mapped to many Android-relevant data capture, credential capture, surveillance, SMS/call, and remote access behaviors. That breadth makes it useful for assessing whether mobile security, identity protection, and SOC workflows can handle a compromised phone scenario, especially where mobile devices are used for authentication or sensitive communications.

ATT&CK does not provide tactics or official detection text for this object in the supplied fields. The description is brief and cites a public report; local detection and risk assessment require environment-specific Android management, mobile security, identity, and network evidence. This summary does not assert current activity, attribution, customer exposure, or guaranteed detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Escobar

Escobar is an Android banking trojan, first detected in March 2021, believed to be a new variant of AbereBot.[1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

16 rows
DomainIDNameRelationship / procedure
MobileT1636.004SMS MessagesSub-technique

Escobar can read SMS messages on the device.[1]

MobileT1512Video Capture

Escobar can take photos using the device cameras.[1]

MobileT1616Call Control

Escobar can initiate phone calls.[1]

MobileT1461Lockscreen Bypass

Escobar can request the `DISABLE_KEYGUARD` permission to disable the device lock screen password.[1]

MobileT1430Location Tracking

Escobar can request coarse and fine location permissions to track the device.[1]

MobileT1409Stored Application Data

Escobar can request the `GET_ACCOUNTS` permission to get the list of accounts on the device, and can collect media files.[1]

MobileT1420File and Directory Discovery

Escobar can access external storage.[1]

MobileT1636.002Call LogSub-technique

Escobar can access the device’s call log.[1]

MobileT1517Access Notifications

Escobar can monitor a device’s notifications.[1]

MobileT1582SMS Control

Escobar can modify, send, and delete SMS messages.[1]

MobileT1663Remote Access Software

Escobar can use VNC to remotely control an infected device.[1]

MobileT1533Data from Local System

Escobar can collect sensitive information, such as Google Authenticator codes.[1]

MobileT1417.001KeyloggingSub-technique

Escobar can collect application keylogs.[1]

MobileT1630.001Uninstall Malicious ApplicationSub-technique

Escobar can uninstall itself and other applications.[1]

MobileT1429Audio Capture

Escobar can record audio from the device’s microphone.[1]

MobileT1417.002GUI Input CaptureSub-technique

Escobar can collect credentials using phishing overlays.[1]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
cfd0926bef0d4f38...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.0Current bundlecfd0926bef0d…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Bleeipng Computer Escobar

    B. Toulas. (2022, March 12). Android malware Escobar steals your Google Authenticator MFA codes. Retrieved September 28, 2023.

    Open source URL
  2. [2]
    Bleeipng Computer Escobar

    B. Toulas. (2022, March 12). Android malware Escobar steals your Google Authenticator MFA codes. Retrieved September 28, 2023.

    Open source URL
  3. [3]
    mitre-attackS1092
    Open source URL
  4. [4]
    mitre-attackS1092
    Open source URL
  5. [5]
    Bleeipng Computer Escobar

    B. Toulas. (2022, March 12). Android malware Escobar steals your Google Authenticator MFA codes. Retrieved September 28, 2023.

    Open source URL
  6. [6]
    Bleeipng Computer Escobar

    B. Toulas. (2022, March 12). Android malware Escobar steals your Google Authenticator MFA codes. Retrieved September 28, 2023.

    Open source URL
  7. [7]
    Bleeipng Computer Escobar

    B. Toulas. (2022, March 12). Android malware Escobar steals your Google Authenticator MFA codes. Retrieved September 28, 2023.

    Open source URL
  8. [8]
    Bleeipng Computer Escobar

    B. Toulas. (2022, March 12). Android malware Escobar steals your Google Authenticator MFA codes. Retrieved September 28, 2023.

    Open source URL
  9. [9]
    Bleeipng Computer Escobar

    B. Toulas. (2022, March 12). Android malware Escobar steals your Google Authenticator MFA codes. Retrieved September 28, 2023.

    Open source URL
  10. [10]
    Bleeipng Computer Escobar

    B. Toulas. (2022, March 12). Android malware Escobar steals your Google Authenticator MFA codes. Retrieved September 28, 2023.

    Open source URL
  11. [11]
    Bleeipng Computer Escobar

    B. Toulas. (2022, March 12). Android malware Escobar steals your Google Authenticator MFA codes. Retrieved September 28, 2023.

    Open source URL
  12. [12]
    Bleeipng Computer Escobar

    B. Toulas. (2022, March 12). Android malware Escobar steals your Google Authenticator MFA codes. Retrieved September 28, 2023.

    Open source URL
  13. [13]
    Bleeipng Computer Escobar

    B. Toulas. (2022, March 12). Android malware Escobar steals your Google Authenticator MFA codes. Retrieved September 28, 2023.

    Open source URL
  14. [14]
    Bleeipng Computer Escobar

    B. Toulas. (2022, March 12). Android malware Escobar steals your Google Authenticator MFA codes. Retrieved September 28, 2023.

    Open source URL
  15. [15]
    Bleeipng Computer Escobar

    B. Toulas. (2022, March 12). Android malware Escobar steals your Google Authenticator MFA codes. Retrieved September 28, 2023.

    Open source URL
  16. [16]
    Bleeipng Computer Escobar

    B. Toulas. (2022, March 12). Android malware Escobar steals your Google Authenticator MFA codes. Retrieved September 28, 2023.

    Open source URL
  17. [17]
    Bleeipng Computer Escobar

    B. Toulas. (2022, March 12). Android malware Escobar steals your Google Authenticator MFA codes. Retrieved September 28, 2023.

    Open source URL
  18. [18]
    Bleeipng Computer Escobar

    B. Toulas. (2022, March 12). Android malware Escobar steals your Google Authenticator MFA codes. Retrieved September 28, 2023.

    Open source URL
  19. [19]
    Bleeipng Computer Escobar

    B. Toulas. (2022, March 12). Android malware Escobar steals your Google Authenticator MFA codes. Retrieved September 28, 2023.

    Open source URL
  20. [20]
    Bleeipng Computer Escobar

    B. Toulas. (2022, March 12). Android malware Escobar steals your Google Authenticator MFA codes. Retrieved September 28, 2023.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.