Threats Tagged 'hook'
View all threats tagged with 'hook'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'hook'
Click on any threat for detailed analysis and mitigation recommendations
ERMAC and HookBot are two branches of one Android banking trojan sold as a service, forking from shared code originating with Cerberus. A copy of the builder, Laravel backend, and React panel leaked in August 2025, enabling unrelated operators to deploy panels with default credentials and keys still in place. The lineage runs Cerberus to ERMAC to Hook, confirmed through source code analysis showing identical database migrations and network protocol structures. HookBot added VNC remote control and 38 new commands while maintaining ERMAC's core. The leaked source includes a Docker stack, Obfuscapk builder, and IP-whitelist firewall that hides panels but leaves the builder port exposed. Operators target 484 apps across 40+ countries including Japanese banks, Brazilian financial institutions, Turkish banks, and cryptocurrency wallets. Detection artifacts survive in builder obfuscator flags and favicons, while panel titles remain easily changed. Join the discussion | AlienVault OTX General | 08/25/2026, 16:29:33 UTC Added: 08/25/2026, 17:22:13 UTC |
Herodotus is a newly discovered Android malware designed to perform device takeover by mimicking human behavior to evade biometric and automated detection. It is distributed via side-loading and targets financial organizations and cryptocurrency wallets, with active campaigns observed in Italy and Brazil and potential for global spread. The malware is offered as Malware-as-a-Service and is linked to the Brokewell malware family. It steals credentials and remotely controls infected devices, using randomized delays between inputs to simulate human interaction. This behavior mimicry complicates detection by security solutions relying on behavioral analysis. The malware’s focus on financial targets and crypto wallets poses significant risks to confidentiality and financial integrity. European organizations, especially in Italy and Poland, are currently targeted and should prepare for potential expansion. Mitigation requires advanced layered security, including strict app installation policies, behavioral anomaly detection tuned for such mimicry, and user education on side-loading risks. Join the discussion | AlienVault OTX General | 10/28/2025, 18:24:45 UTC Added: 10/28/2025, 19:25:46 UTC |
The complete source code for ERMAC V3.0, an advanced banking trojan, was discovered and analyzed, providing rare insight into this active Malware-as-a-Service platform. ERMAC has evolved to target over 700 financial and cryptocurrency apps, employing sophisticated form injection techniques and encrypted communications. The analysis revealed critical vulnerabilities, including hardcoded credentials and default tokens, which could be exploited to disrupt operations. The malware's infrastructure consists of a Laravel-based C2 backend, React control panel, Golang exfiltration service, and an obfuscated Android backdoor. This comprehensive examination exposes the operational risks of the MaaS model and equips defenders with concrete methods to track, detect, and disrupt active ERMAC campaigns. Join the discussion | AlienVault OTX General | 08/15/2025, 05:29:20 UTC Added: 08/15/2025, 12:47:47 UTC |
Showing 1 to 3 of 3 results