Based on the malware’s panel, we named this malware variant Hook. ... Hook now joins the very dangerous ranks of malware which is able to perform a full attack chain from infection to fraudulent transaction.
HOOK
Hook is an Android banking trojan derived from the ERMAC codebase and associated with the threat actor DukeEugene.
Profile source: Mallory opens in a new tabHOOK
Family profile
Hook is an Android banking trojan derived from the ERMAC codebase and associated with the threat actor DukeEugene. It targets banking applications, cryptocurrency wallets, and other financial services across multiple regions. Hook combines credential-harvesting overlays and keylogging with Android Accessibility Services abuse to support full device takeover and fraudulent transaction execution. Its remote-control functionality, often marketed as VNC, can simulate user interface actions, capture screenshots, enter text, unlock devices, and otherwise operate victim devices interactively. Hook can also steal SMS messages, contacts, files, geolocation data, cryptocurrency-wallet recovery phrases, and authentication-related data, and includes functions for call forwarding, USSD execution, and WhatsApp interaction. It communicates with command-and-control infrastructure using HTTP and WebSocket-based channels, enabling real-time operator control, file management, and remote fraud operations. Hook has been offered as a botnet rental service and represents a mature malware-as-a-service-oriented Android financial-fraud threat.
Capabilities
- Credential Theft
- Crypto Theft
- Exfiltration
- Keylogging
- Reconnaissance
- Session Hijacking
- Spoofing
Reported operators
Threat actors
2 named in public reportingThe mobile threat landscape has been shaped over the years by well-established banking Trojan families such as Anatsa, Octo, Hook...
MITRE ATT&CK