ERMAC is an Android banking trojan that emerged in 2021 and is widely assessed as a Cerberus-derived malware family. It is associated with the threat actor DukeEugene and has been offered as a malware-as-a-service operation on underground forums. ERMAC has targeted hundreds of banking, financial, cryptocurrency, social media, and ecommerce applications, with observed campaigns including strong focus on Poland as well as broader international targeting.
The malware primarily abuses Android Accessibility Services to obtain intrusive control over the device and enable credential theft. After installation, it commonly prompts the victim to grant accessibility privileges, then inventories installed applications and reports them to command-and-control infrastructure. Based on the installed app list, operators can deliver tailored overlay or webinject content for selected targets. When a victim opens a targeted application, ERMAC displays phishing overlays to capture credentials and other sensitive data. Reported capabilities also include keylogging, theft of SMS messages and authentication tokens, contact and account harvesting, call forwarding, USSD execution, retrieval of installed apps, launching applications, and management of webinjects from the server side. Some reporting also describes theft of Google authentication tokens and cryptocurrency wallet seed phrases, enabling account takeover and crypto theft.
ERMAC variants have used updated obfuscation and encryption compared with Cerberus, including encrypted strings and encrypted command-and-control communications, while retaining command structures and core logic closely aligned with the Cerberus codebase. Later variants such as ERMAC 2.0 expanded the number of targeted applications and continued to rely on encrypted injection delivery and accessibility abuse.
Observed delivery has included fake browser update pages, phishing sites impersonating legitimate services, trojanized Android applications, Google Play droppers, third-party droppers such as DawDropper and SecuriDropper, app-binding services such as Zombinder, deceptive websites, Discord-based distribution, and malicious apps masquerading as legitimate utilities or service applications. ERMAC has also appeared in multi-platform criminal campaigns where Android infections were paired with Windows malware distribution.
ERMAC is part of a broader lineage of Cerberus-derived Android banking malware that includes later forks such as Hook. Its continued development, MaaS commercialization, and integration into outsourced dropper and distribution ecosystems make it a persistent mobile banking threat.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
On July 23 a forum post appeared regarding a new Android banking trojan. The attached screenshots show that it is named ERMAC.
This new malware variant, clearly based on Ermac... From this thread, we can confidently say that Hook is the latest development of Ermac.
In the first case, we observed Brunhilda posing as a QR code creator app, Brunhilda dropped samples from established families, like Hydra, as well as novel ones, like Ermac.
...linked to a known threat actor in mobile threat landscape, “sybra”, that we already observed operating one of the Ermac forks, "MetaDroid"...
22 distinct techniques documented for this family, organized by ATT&CK tactic.
It was distributed through a fake one-page website containing only two buttons... the “Download for Android” button leads to downloading samples of Ermac... modified legitimate application was downloaded from malicious website mimicking the original website of the application. Victim is navigated there through malicious advertisement.
ERMAC abuses a built-in feature in the Android Accessibility Suite intended for users with disabilities.
It started with Wi-Fi authorization app which in fact was Ermac with obfuscation of the malicious code.
startInject Triggers the overlay attack against the specified application | push Shows a push notification (clicking on the notification will result in launching specified app)
Ermac.C, having the following capabilities... Keylogging... It is worth noting that authors of Xenomorph... enhanced with keylogging functionality
startInject Triggers the overlay attack against the specified application | push Shows a push notification (clicking on the notification will result in launching specified app)
It uses almost identical data structures when communicating with the C2... Compared to the original Cerberus, ERMAC uses different encryption scheme in communication with the C2: the data is encrypted with AES-128-CBC
The dropper is responsible for installing a secondary payload, typically malware (spyware or banking Trojans), onto the victim's device.
The most important addition in terms of capabilities comes in the form of what criminals call VNC... In the case of Hook, this is implemented using the Accessibility Services to interact with the different UI elements required to perform a wide array of operations.
201 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan family referenced as the predecessor/family from which Hook descends.
Android banking trojan referenced for comparison (source code leaked); no additional details provided in the excerpt.
Android banking trojan with expanded form-injection and data theft targeting 700+ banking/shopping/crypto apps; source code leak exposed infrastructure weaknesses (per summary).
Android banking trojan family observed in multiple regions (including South Korea) as part of broader banking malware activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.