Initially, the Brunhilda droppers were deploying a variety of Android malware applications, like for example samples of the malware family Alien.
Alien
Alien is an Android banking trojan operated as a malware-as-a-service offering and derived from the Cerberus v1 codebase.
Profile source: Mallory opens in a new tabAlien
Family profile
Alien is an Android banking trojan operated as a malware-as-a-service offering and derived from the Cerberus v1 codebase. First observed in 2020, it is associated with financially motivated Android fraud operations and has been distributed through staged Google Play dropper campaigns masquerading as legitimate utility, scanner, cryptocurrency, and fitness applications. These droppers can selectively deliver the payload and solicit installation of a purported update from unknown sources.
Alien abuses Android Accessibility Services to support overlay-based credential theft and can collect SMS messages, notifications, contacts, device information, installed-application inventories, location data, and Google Authenticator secrets used for two-factor authentication. It supports keylogging, SMS harvesting and forwarding, call forwarding, USSD requests, arbitrary web-page display, application installation, launch and removal, screen locking, and remote access functions implemented through TeamViewer-based functionality. It also includes modularity, auxiliary command-and-control resilience, application-icon hiding, removal prevention, and emulator detection.
Alien has been linked to the commercial-surveillance ecosystem surrounding Cytrox/Intellexa. In limited 2021 Android exploit campaigns attributed to government-backed Cytrox customers, Alien was deployed following spearphishing-led Chrome and Android exploit chains and used as a precursor to load the Predator spyware implant. Alien's Cerberus lineage and its overlap with later Android banking malware development contributed to its prominence after Cerberus operations declined and its source code was leaked.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Keylogging
- Persistence
- Post Exploitation
Reported operators
Threat actors
4 named in public reportingThe ultimate goal of the operation, the researchers assessed, was to distribute a malware dubbed Alien, which acts as a precursor for loading Predator onto infected Android devices.
Some samples were observed having more than 50.000+ installations, and dropping the android trojan Alien.
Predator от Cytrox / Intellexa работает двухкомпонентно: Alien ломает устройство, Predator устанавливает модули слежки.
Exploited software
Vulnerabilities linked to Alien
5 CVEsMITRE ATT&CK
Alien in ATT&CK
48 distinct techniquesTechniques
48 techniquesReporting
Research mentioning Alien
ERMAC 2.0: Perfecting the Art of Account Takeover | Intel 471
ERMAC evolved into a more capable Android banking trojan that abuses Accessibility Services to steal credentials, intercept SMS codes, and capture Google authentication tokens, allowing attackers to bypass multi-factor authentication and take over banking, financial, ecommerce, and cryptocurrency accounts. Researchers said ERMAC 2.0, derived from leaked Cerberus code and sold through the malware-as-a-service ecosystem, expanded its targeting from 378 applications to 467 and used encrypted communications, phishing overlays, and app-list reconnaissance to fetch tailored injection content from command-and-control servers. The malware was distributed through fake browser update pages, phishing sites impersonating brands such as Bolt Food, trojanized Android apps, and Google Play dropper applications that helped infect more than 300,000 devices across multiple banking trojan campaigns. ThreatFabric also linked ERMAC delivery to the Zombinder app-binding service, which hides malicious payloads inside working Android apps, and observed overlapping infrastructure that also pushed Windows malware including Erbium Stealer, Laplas Clipper, and Aurora Stealer, underscoring a broader criminal ecosystem built around outsourced obfuscation, staging, and malware delivery.