Threats Tagged 'source code leak'
View all threats tagged with 'source code leak'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'source code leak'
Click on any threat for detailed analysis and mitigation recommendations
ERMAC and HookBot are two branches of one Android banking trojan sold as a service, forking from shared code originating with Cerberus. A copy of the builder, Laravel backend, and React panel leaked in August 2025, enabling unrelated operators to deploy panels with default credentials and keys still in place. The lineage runs Cerberus to ERMAC to Hook, confirmed through source code analysis showing identical database migrations and network protocol structures. HookBot added VNC remote control and 38 new commands while maintaining ERMAC's core. The leaked source includes a Docker stack, Obfuscapk builder, and IP-whitelist firewall that hides panels but leaves the builder port exposed. Operators target 484 apps across 40+ countries including Japanese banks, Brazilian financial institutions, Turkish banks, and cryptocurrency wallets. Detection artifacts survive in builder obfuscator flags and favicons, while panel titles remain easily changed. Join the discussion | AlienVault OTX General | 08/25/2026, 16:29:33 UTC Added: 08/25/2026, 17:22:13 UTC |
The complete source code for ERMAC V3.0, an advanced banking trojan, was discovered and analyzed, providing rare insight into this active Malware-as-a-Service platform. ERMAC has evolved to target over 700 financial and cryptocurrency apps, employing sophisticated form injection techniques and encrypted communications. The analysis revealed critical vulnerabilities, including hardcoded credentials and default tokens, which could be exploited to disrupt operations. The malware's infrastructure consists of a Laravel-based C2 backend, React control panel, Golang exfiltration service, and an obfuscated Android backdoor. This comprehensive examination exposes the operational risks of the MaaS model and equips defenders with concrete methods to track, detect, and disrupt active ERMAC campaigns. Join the discussion | AlienVault OTX General | 08/15/2025, 05:29:20 UTC Added: 08/15/2025, 12:47:47 UTC |
Showing 1 to 2 of 2 results