Threats Tagged 'ermac'
View all threats tagged with 'ermac'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ermac'
Click on any threat for detailed analysis and mitigation recommendations
ERMAC and HookBot are Android banking trojans derived from Cerberus source code. A leak of HookBot's builder, backend, and panel source code in August 2025 exposed default credentials and keys, allowing unauthorized operators to deploy malicious panels. HookBot extends ERMAC with VNC remote control and additional commands. The leaked source includes deployment tools such as a Docker stack and an IP-whitelist firewall that hides panels but leaves the builder port exposed. Operators target hundreds of apps across more than 40 countries, including banks and cryptocurrency wallets. Detection artifacts persist in obfuscation flags and favicons, but panel titles can be easily changed. Join the discussion | AlienVault OTX General | 08/25/2026, 16:29:33 UTC Added: 08/25/2026, 17:22:13 UTC |
Perseus is a new Android threat that builds upon earlier malware families like Cerberus and Phoenix. It enables real-time monitoring and interaction with infected devices through Accessibility-based remote sessions, allowing full Device Takeover. The malware focuses on extracting high-value personal information, including monitoring user notes. It employs strong anti-analysis measures to evade detection. Perseus is primarily distributed through IPTV applications, targeting users in Turkey and Italy. Its capabilities include overlay attacks, keylogging, and systematic exploration of note-taking apps. The malware performs extensive environment checks to detect analysis conditions and assess device risk. Perseus represents the ongoing evolution of mobile malware, adapting to remain effective in an increasingly secure mobile environment. Join the discussion | AlienVault OTX General | 03/19/2026, 11:00:48 UTC Added: 03/19/2026, 13:53:28 UTC |
The complete source code for ERMAC V3.0, an advanced banking trojan, was discovered and analyzed, providing rare insight into this active Malware-as-a-Service platform. ERMAC has evolved to target over 700 financial and cryptocurrency apps, employing sophisticated form injection techniques and encrypted communications. The analysis revealed critical vulnerabilities, including hardcoded credentials and default tokens, which could be exploited to disrupt operations. The malware's infrastructure consists of a Laravel-based C2 backend, React control panel, Golang exfiltration service, and an obfuscated Android backdoor. This comprehensive examination exposes the operational risks of the MaaS model and equips defenders with concrete methods to track, detect, and disrupt active ERMAC campaigns. Join the discussion | AlienVault OTX General | 08/15/2025, 05:29:20 UTC Added: 08/15/2025, 12:47:47 UTC |
Showing 1 to 3 of 3 results