On July 23 a forum post appeared regarding a new Android banking trojan. The attached screenshots show that it is named ERMAC.
ERMAC
ERMAC is an Android banking trojan that emerged in 2021 and is widely assessed as a Cerberus-derived malware family.
Profile source: Mallory opens in a new tabERMAC
Family profile
ERMAC is an Android banking trojan that emerged in 2021 and is widely assessed as a Cerberus-derived malware family. It is associated with the threat actor DukeEugene and has been offered as a malware-as-a-service operation on underground forums. ERMAC has targeted hundreds of banking, financial, cryptocurrency, social media, and ecommerce applications, with observed campaigns including strong focus on Poland as well as broader international targeting.
The malware primarily abuses Android Accessibility Services to obtain intrusive control over the device and enable credential theft. After installation, it commonly prompts the victim to grant accessibility privileges, then inventories installed applications and reports them to command-and-control infrastructure. Based on the installed app list, operators can deliver tailored overlay or webinject content for selected targets. When a victim opens a targeted application, ERMAC displays phishing overlays to capture credentials and other sensitive data. Reported capabilities also include keylogging, theft of SMS messages and authentication tokens, contact and account harvesting, call forwarding, USSD execution, retrieval of installed apps, launching applications, and management of webinjects from the server side. Some reporting also describes theft of Google authentication tokens and cryptocurrency wallet seed phrases, enabling account takeover and crypto theft.
ERMAC variants have used updated obfuscation and encryption compared with Cerberus, including encrypted strings and encrypted command-and-control communications, while retaining command structures and core logic closely aligned with the Cerberus codebase. Later variants such as ERMAC 2.0 expanded the number of targeted applications and continued to rely on encrypted injection delivery and accessibility abuse.
Observed delivery has included fake browser update pages, phishing sites impersonating legitimate services, trojanized Android applications, Google Play droppers, third-party droppers such as DawDropper and SecuriDropper, app-binding services such as Zombinder, deceptive websites, Discord-based distribution, and malicious apps masquerading as legitimate utilities or service applications. ERMAC has also appeared in multi-platform criminal campaigns where Android infections were paired with Windows malware distribution.
ERMAC is part of a broader lineage of Cerberus-derived Android banking malware that includes later forks such as Hook. Its continued development, MaaS commercialization, and integration into outsourced dropper and distribution ecosystems make it a persistent mobile banking threat.
Capabilities
- Credential Theft
- Crypto Theft
- Defense Evasion
- Exfiltration
- Keylogging
- Post Exploitation
Reported operators
Threat actors
4 named in public reportingThis new malware variant, clearly based on Ermac... From this thread, we can confidently say that Hook is the latest development of Ermac.
In the first case, we observed Brunhilda posing as a QR code creator app, Brunhilda dropped samples from established families, like Hydra, as well as novel ones, like Ermac.
...linked to a known threat actor in mobile threat landscape, “sybra”, that we already observed operating one of the Ermac forks, "MetaDroid"...
MITRE ATT&CK
ERMAC in ATT&CK
22 distinct techniquesTechniques
22 techniquesReporting
Research mentioning ERMAC
ERMAC 2.0: Perfecting the Art of Account Takeover | Intel 471
ERMAC evolved into a more capable Android banking trojan that abuses Accessibility Services to steal credentials, intercept SMS codes, and capture Google authentication tokens, allowing attackers to bypass multi-factor authentication and take over banking, financial, ecommerce, and cryptocurrency accounts. Researchers said ERMAC 2.0, derived from leaked Cerberus code and sold through the malware-as-a-service ecosystem, expanded its targeting from 378 applications to 467 and used encrypted communications, phishing overlays, and app-list reconnaissance to fetch tailored injection content from command-and-control servers. The malware was distributed through fake browser update pages, phishing sites impersonating brands such as Bolt Food, trojanized Android apps, and Google Play dropper applications that helped infect more than 300,000 devices across multiple banking trojan campaigns. ThreatFabric also linked ERMAC delivery to the Zombinder app-binding service, which hides malicious payloads inside working Android apps, and observed overlapping infrastructure that also pushed Windows malware including Erbium Stealer, Laplas Clipper, and Aurora Stealer, underscoring a broader criminal ecosystem built around outsourced obfuscation, staging, and malware delivery.