Skip to content

Alien

Alien is an Android banking trojan operated as a malware-as-a-service offering and derived from the Cerberus v1 codebase.

Profile source: Mallory opens in a new tab

Alien

Family profile

Alien is an Android banking trojan operated as a malware-as-a-service offering and derived from the Cerberus v1 codebase. First observed in 2020, it is associated with financially motivated Android fraud operations and has been distributed through staged Google Play dropper campaigns masquerading as legitimate utility, scanner, cryptocurrency, and fitness applications. These droppers can selectively deliver the payload and solicit installation of a purported update from unknown sources.

Alien abuses Android Accessibility Services to support overlay-based credential theft and can collect SMS messages, notifications, contacts, device information, installed-application inventories, location data, and Google Authenticator secrets used for two-factor authentication. It supports keylogging, SMS harvesting and forwarding, call forwarding, USSD requests, arbitrary web-page display, application installation, launch and removal, screen locking, and remote access functions implemented through TeamViewer-based functionality. It also includes modularity, auxiliary command-and-control resilience, application-icon hiding, removal prevention, and emulator detection.

Alien has been linked to the commercial-surveillance ecosystem surrounding Cytrox/Intellexa. In limited 2021 Android exploit campaigns attributed to government-backed Cytrox customers, Alien was deployed following spearphishing-led Chrome and Android exploit chains and used as a precursor to load the Predator spyware implant. Alien's Cerberus lineage and its overlap with later Android banking malware development contributed to its prominence after Cerberus operations declined and its source code was leaked.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation

Reported operators

Threat actors

4 named in public reporting
Brunhilda Project

Initially, the Brunhilda droppers were deploying a variety of Android malware applications, like for example samples of the malware family Alien.

Cytrox

The ultimate goal of the operation, the researchers assessed, was to distribute a malware dubbed Alien, which acts as a precursor for loading Predator onto infected Android devices.

Brunhilda

Some samples were observed having more than 50.000+ installations, and dropping the android trojan Alien.

Intellexa

Predator от Cytrox / Intellexa работает двухкомпонентно: Alien ломает устройство, Predator устанавливает модули слежки.

Exploited software

Vulnerabilities linked to Alien

5 CVEs

MITRE ATT&CK

Alien in ATT&CK

48 distinct techniques

Reporting

Research mentioning Alien

Jan 1
Intel471

ERMAC 2.0: Perfecting the Art of Account Takeover | Intel 471

ERMAC evolved into a more capable Android banking trojan that abuses Accessibility Services to steal credentials, intercept SMS codes, and capture Google authentication tokens, allowing attackers to bypass multi-factor authentication and take over banking, financial, ecommerce, and cryptocurrency accounts. Researchers said ERMAC 2.0, derived from leaked Cerberus code and sold through the malware-as-a-service ecosystem, expanded its targeting from 378 applications to 467 and used encrypted communications, phishing overlays, and app-list reconnaissance to fetch tailored injection content from command-and-control servers. The malware was distributed through fake browser update pages, phishing sites impersonating brands such as Bolt Food, trojanized Android apps, and Google Play dropper applications that helped infect more than 300,000 devices across multiple banking trojan campaigns. ThreatFabric also linked ERMAC delivery to the Zombinder app-binding service, which hides malicious payloads inside working Android apps, and observed overlapping infrastructure that also pushed Windows malware including Erbium Stealer, Laplas Clipper, and Aurora Stealer, underscoring a broader criminal ecosystem built around outsourced obfuscation, staging, and malware delivery.

Dec 8
Threatfabric

Zombinder: new obfuscation service used by Ermac, now distributed next to desktop stealers

May 25
Cyble Blog Historic

ERMAC Malware Back In Action: New Threats And Attack Methods

Nov 17
Threatfabric

Deceive the Heavens to Cross the sea

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.