DukeEugene is a financially motivated cybercriminal threat actor associated with the promotion and rental of Android malware through a malware-as-a-service model. The actor is known for advertising the Android banking trojan ERMAC and the related malware family Hook on underground forums, facilitating customer communications, and providing access to management infrastructure for operators. DukeEugene has been linked to ERMAC, an Android banking trojan derived from Cerberus that abuses Android accessibility features to monitor application launches, present phishing overlays, steal credentials, and collect authentication material. ERMAC has targeted hundreds of mobile banking, financial, and ecommerce applications and has been described as capable of bypassing multi-factor authentication through theft of Google authentication tokens and SMS-delivered tokens. Hook has been assessed as built on ERMAC source code while adding substantial functionality, including screen streaming, front-camera capture, theft of Google login cookies, and expanded theft of cryptocurrency wallet recovery seeds. The actor has also claimed authorship of the BlackRock Android banking trojan. Activity associated with DukeEugene reflects a mature criminal service ecosystem centered on mobile credential theft and account takeover, with emphasis on scalable distribution, operator support, and post-compromise data collection. Known aliases include Duke Eugene and Eugene.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
156 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Promotes and rents ERMAC as malware-as-a-service on underground forums, manages client communications, and provides access to the malware control panel; also claimed to be the 2020 author of the BlackRock Android banking trojan.
Advertises Android malware families Hook and ERMAC; Hook is assessed to be based on ERMAC source code and adds expanded capabilities (e.g., screen streaming, camera capture, cookie theft, crypto seed theft).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.