ERMAC is an Android banking trojan that emerged in 2021 and derives substantially from leaked Cerberus source code. It is distributed through a malware-as-a-service model and has been advertised and rented by DukeEugene, an actor also associated with BlackRock. Early campaigns targeted Poland, while subsequent versions expanded their target lists to hundreds of banking, payment, cryptocurrency, e-commerce, and social applications internationally. ERMAC 2.0 advertised support for credential theft from 467 applications.
ERMAC abuses Android Accessibility Services to monitor application launches, manipulate the interface, and display credential-stealing HTML overlays over legitimate applications. It enumerates installed applications and retrieves matching injection modules from its command-and-control server. Its capabilities include harvesting device accounts, contacts, SMS messages, and authentication codes; sending SMS messages; forwarding calls; executing USSD requests; launching applications; and updating modules. ERMAC.C additionally supports keylogging, Gmail data theft, and cryptocurrency-wallet seed phrase theft. Interception of authentication codes enables operators to undermine multifactor authentication. Variants use packing, encrypted strings, and encrypted command-and-control communications to complicate analysis and detection.
Distribution includes fake browser updates, phishing websites, malicious download pages, and applications impersonating browsers, delivery services, government services, and other legitimate software. ERMAC has also been delivered through Google Play dropper campaigns, trojanized functional applications produced with Zombinder, and SecuriDropper campaigns using Discord. SecuriDropper's session-based installation technique allows delivered payloads to bypass Android 13 Restricted Settings and subsequently request sensitive permissions. Hook originated as an ERMAC-derived branch with expanded remote-control capabilities; later ERMAC 3.0 server components share substantial code with HookBot.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ERMAC and HookBot are two branches of one Android banking trojan sold as a service.
On July 23 a forum post appeared regarding a new Android banking trojan. The attached screenshots show that it is named ERMAC.
In the first case, we observed Brunhilda posing as a QR code creator app, Brunhilda dropped samples from established families, like Hydra, as well as novel ones, like Ermac.
...linked to a known threat actor in mobile threat landscape, “sybra”, that we already observed operating one of the Ermac forks, "MetaDroid"...
22 distinct techniques documented for this family, organized by ATT&CK tactic.
It was distributed through a fake one-page website containing only two buttons... the “Download for Android” button leads to downloading samples of Ermac... modified legitimate application was downloaded from malicious website mimicking the original website of the application. Victim is navigated there through malicious advertisement.
ERMAC abuses a built-in feature in the Android Accessibility Suite intended for users with disabilities.
It started with Wi-Fi authorization app which in fact was Ermac with obfuscation of the malicious code.
startInject Triggers the overlay attack against the specified application | push Shows a push notification (clicking on the notification will result in launching specified app)
Ermac.C, having the following capabilities... Keylogging... It is worth noting that authors of Xenomorph... enhanced with keylogging functionality
startInject Triggers the overlay attack against the specified application | push Shows a push notification (clicking on the notification will result in launching specified app)
It uses almost identical data structures when communicating with the C2... Compared to the original Cerberus, ERMAC uses different encryption scheme in communication with the C2: the data is encrypted with AES-128-CBC
The dropper is responsible for installing a secondary payload, typically malware (spyware or banking Trojans), onto the victim's device.
The most important addition in terms of capabilities comes in the form of what criminals call VNC... In the case of Hook, this is implemented using the Accessibility Services to interact with the different UI elements required to perform a wide array of operations.
221 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan distributed through sideloaded APKs. It abuses accessibility permissions to display credential-stealing overlays and intercept confirmation codes. Initially derived from leaked Cerberus code, later versions incorporated Hook capabilities. Its leaked infrastructure includes a Laravel backend, React panel, relay, and APK builder. The bundled 484 overlays indicate worldwide targeting intent, not confirmed victims.
Android banking trojan family referenced as the predecessor/family from which Hook descends.
Android banking trojan referenced for comparison (source code leaked); no additional details provided in the excerpt.
Android banking trojan with expanded form-injection and data theft targeting 700+ banking/shopping/crypto apps; source code leak exposed infrastructure weaknesses (per summary).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.