BlackRock is an Android banking trojan first identified in May 2020. It derives from the publicly released Xerxes source code and belongs to the Android LokiBot lineage. Associated with the cybercriminal actor DukeEugene, it has been offered through a malware-as-a-service model. BlackRock shares an operator with ERMAC but has a distinct code lineage: ERMAC derives from Cerberus. BlackRock targets hundreds of banking, cryptocurrency, shopping, email, social networking, messaging, and other applications. Distribution campaigns have impersonated Google updates and used a counterfeit Clubhouse website to deliver a sideloaded Android application.
After installation, BlackRock hides its launcher icon and prompts the victim to enable Android Accessibility Services. It abuses that access to grant additional permissions, identify foreground applications, and display application-specific credential-stealing overlays or generic payment-card collection forms. Overlay content is downloaded and stored locally. Its capabilities include targeted keylogging, SMS interception and forwarding, notification theft, device-information collection, and remote commands to launch applications, send messages, spam contacts, and control screen locking. Intercepted SMS messages can expose authentication codes. BlackRock also abuses Android managed work profiles to obtain administrative privileges and resists removal by redirecting users away from security and device-cleaning applications.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
BlackRock embeds following set of features... Device info collection
startInject Triggers the overlay attack against the specified application
71 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Trojan operated by DukeEugene from May 2020 and descended from Xerxes rather than Cerberus. A buyer rebranded it as AmpleBot and used that branding to scam customers. It provides background on ERMAC's operator history, not its source-code ancestry.
Android banking trojan attributed in the content to DukeEugene and mentioned as a prior MaaS offering related to the ERMAC operator ecosystem.
Android banking trojan previously associated with DukeEugene. The content assesses that its operators likely shifted from BlackRock to ERMAC and notes overlapping C2 infrastructure.
Android trojan disguised as a Clubhouse app that steals credentials via overlay attacks, intercepts SMS messages to bypass SMS-based 2FA, and abuses accessibility services to gain extensive control over the device.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.