BlackRock is an Android banking trojan first observed in 2020 and associated with an operator later linked to the DukeEugene persona. It is derived from the Xerxes codebase, which itself descends from the LokiBot Android malware lineage. BlackRock was notable for combining established mobile banking-trojan tradecraft with unusually broad targeting beyond banks, including cryptocurrency, shopping, email, social media, messaging, business, transportation, lifestyle, and dating applications.
On infected devices, BlackRock abuses Android Accessibility Services to monitor foreground applications, grant itself additional permissions, and enable credential-harvesting workflows. It hides its icon, communicates with command-and-control infrastructure, and can deploy overlay screens tailored to targeted applications in order to steal usernames, passwords, and payment-card data. It also supports SMS theft, notification theft, keylogging, device-information collection, contact abuse, and anti-removal behavior. Reported command support includes sending and harvesting SMS messages, spamming contacts, launching applications, locking the device to the home screen, dismissing notifications, and requesting elevated privileges.
A distinguishing feature was its abuse of Android work profiles to create a managed profile and obtain administrative control, which strengthened persistence and resistance to removal. BlackRock also redirected victims away from security and device-cleaning tools to hinder remediation. Overlay content was maintained locally on the device and downloaded in app-specific packages, enabling scalable credential theft across a large target set.
BlackRock was distributed through social-engineering lures, including fake Google update prompts and a fake Clubhouse Android application campaign that exploited demand for an Android version before an official release existed. In those campaigns, victims were enticed to sideload a malicious APK from a spoofed landing page. Once installed, the malware requested accessibility permissions and then used overlays and SMS interception to compromise accounts, including accounts protected by SMS-based two-factor authentication.
BlackRock has been described as capable of stealing credentials from hundreds of online services and represented a significant evolution in Android banking malware by expanding monetization beyond traditional financial fraud. The actor associated with BlackRock was later assessed to have shifted operations toward ERMAC, another Android banking trojan derived from Cerberus, and some reporting links ERMAC operations to BlackRock-associated actors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Our investigation shows that ERMAC is almost fully based on the well-known banking trojan Cerberus, and is being operated by BlackRock actor(s).
13 distinct techniques documented for this family, organized by ATT&CK tactic.
BlackRock embeds following set of features... Device info collection
startInject Triggers the overlay attack against the specified application
71 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan attributed in the content to DukeEugene and mentioned as a prior MaaS offering related to the ERMAC operator ecosystem.
Android banking trojan previously associated with DukeEugene. The content assesses that its operators likely shifted from BlackRock to ERMAC and notes overlapping C2 infrastructure.
Android trojan disguised as a Clubhouse app that steals credentials via overlay attacks, intercepts SMS messages to bypass SMS-based 2FA, and abuses accessibility services to gain extensive control over the device.
Mentioned only as another malware whose author commented on and discussed Alien/Cerberus in underground forum exchanges.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.