Skip to content

ERMAC

ERMAC is an Android banking trojan that emerged in 2021 and is widely assessed as a Cerberus-derived malware family.

Profile source: Mallory opens in a new tab

ERMAC

Family profile

ERMAC is an Android banking trojan that emerged in 2021 and is widely assessed as a Cerberus-derived malware family. It is associated with the threat actor DukeEugene and has been offered as a malware-as-a-service operation on underground forums. ERMAC has targeted hundreds of banking, financial, cryptocurrency, social media, and ecommerce applications, with observed campaigns including strong focus on Poland as well as broader international targeting.

The malware primarily abuses Android Accessibility Services to obtain intrusive control over the device and enable credential theft. After installation, it commonly prompts the victim to grant accessibility privileges, then inventories installed applications and reports them to command-and-control infrastructure. Based on the installed app list, operators can deliver tailored overlay or webinject content for selected targets. When a victim opens a targeted application, ERMAC displays phishing overlays to capture credentials and other sensitive data. Reported capabilities also include keylogging, theft of SMS messages and authentication tokens, contact and account harvesting, call forwarding, USSD execution, retrieval of installed apps, launching applications, and management of webinjects from the server side. Some reporting also describes theft of Google authentication tokens and cryptocurrency wallet seed phrases, enabling account takeover and crypto theft.

ERMAC variants have used updated obfuscation and encryption compared with Cerberus, including encrypted strings and encrypted command-and-control communications, while retaining command structures and core logic closely aligned with the Cerberus codebase. Later variants such as ERMAC 2.0 expanded the number of targeted applications and continued to rely on encrypted injection delivery and accessibility abuse.

Observed delivery has included fake browser update pages, phishing sites impersonating legitimate services, trojanized Android applications, Google Play droppers, third-party droppers such as DawDropper and SecuriDropper, app-binding services such as Zombinder, deceptive websites, Discord-based distribution, and malicious apps masquerading as legitimate utilities or service applications. ERMAC has also appeared in multi-platform criminal campaigns where Android infections were paired with Windows malware distribution.

ERMAC is part of a broader lineage of Cerberus-derived Android banking malware that includes later forks such as Hook. Its continued development, MaaS commercialization, and integration into outsourced dropper and distribution ecosystems make it a persistent mobile banking threat.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Post Exploitation

Reported operators

Threat actors

4 named in public reporting
BlackRock actor(s)

On July 23 a forum post appeared regarding a new Android banking trojan. The attached screenshots show that it is named ERMAC.

DukeEugene

This new malware variant, clearly based on Ermac... From this thread, we can confidently say that Hook is the latest development of Ermac.

Brunhilda

In the first case, we observed Brunhilda posing as a QR code creator app, Brunhilda dropped samples from established families, like Hydra, as well as novel ones, like Ermac.

sybra

...linked to a known threat actor in mobile threat landscape, “sybra”, that we already observed operating one of the Ermac forks, "MetaDroid"...

MITRE ATT&CK

ERMAC in ATT&CK

22 distinct techniques

Reporting

Research mentioning ERMAC

Jan 1
Intel471

ERMAC 2.0: Perfecting the Art of Account Takeover | Intel 471

ERMAC evolved into a more capable Android banking trojan that abuses Accessibility Services to steal credentials, intercept SMS codes, and capture Google authentication tokens, allowing attackers to bypass multi-factor authentication and take over banking, financial, ecommerce, and cryptocurrency accounts. Researchers said ERMAC 2.0, derived from leaked Cerberus code and sold through the malware-as-a-service ecosystem, expanded its targeting from 378 applications to 467 and used encrypted communications, phishing overlays, and app-list reconnaissance to fetch tailored injection content from command-and-control servers. The malware was distributed through fake browser update pages, phishing sites impersonating brands such as Bolt Food, trojanized Android apps, and Google Play dropper applications that helped infect more than 300,000 devices across multiple banking trojan campaigns. ThreatFabric also linked ERMAC delivery to the Zombinder app-binding service, which hides malicious payloads inside working Android apps, and observed overlapping infrastructure that also pushed Windows malware including Erbium Stealer, Laplas Clipper, and Aurora Stealer, underscoring a broader criminal ecosystem built around outsourced obfuscation, staging, and malware delivery.

Dec 8
Threatfabric

Zombinder: new obfuscation service used by Ermac, now distributed next to desktop stealers

May 25
Cyble Blog Historic

ERMAC Malware Back In Action: New Threats And Attack Methods

Nov 17
Threatfabric

Deceive the Heavens to Cross the sea

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.