The mobile threat landscape has been shaped over the years by well-established banking Trojan families such as Anatsa, Octo, Hook...
HOOK
Hook is an Android banking trojan descended from ERMAC and advertised alongside ERMAC by the threat actor DukeEugene.
Profile source: Mallory opens in a new tabHOOK
Family profile
Hook is an Android banking trojan descended from ERMAC and advertised alongside ERMAC by the threat actor DukeEugene. Multiple sources in the content describe it as one of the most capable Android banking trojans in active circulation. Hook combines traditional banking-trojan overlay injection attacks with VNC-based remote control, enabling hands-on control of infected Android devices. NCC Group concluded that Hook is based on ERMAC source code rather than being written from scratch, and reported that it adds 38 additional commands over ERMAC, including screen streaming, front-camera photo capture, Google login cookie theft, and expanded cryptocurrency wallet recovery-seed theft.
The malware’s documented capabilities include SMS theft, call control, contact theft, keylogging, Gmail data theft, screenshots, application control, location tracking, WhatsApp messaging, USSD execution, seed phrase theft, push-notification spoofing, Android AccountManager theft, VNC remote access, file management, phishing overlays, arbitrary URL opening, and self-destruct functionality. Researchers analyzing a live Hook command-and-control panel also identified frontend routes and command vocabulary associated with banks, cards, cryptocurrency, email, injections, stealer, wallet, statistics, and user management, reinforcing its role as a full-featured Android banking malware platform.
A live Hook C2 panel was analyzed at 31.57.216.126 on 2026-03-07. The infrastructure exposed an nginx-hosted React frontend on port 80, a Laravel/PHP API backend on port 8089, a Socket.IO event service on port 3434, a WebSocket service for VNC and file management on port 8000, and an internet-exposed MySQL 8.0.31 database on port 3306. The panel supported English, Turkish, Russian, and Traditional Chinese. Researchers confirmed 24 live API endpoints and observed weak operational security, including unauthenticated Socket.IO access, an API route lacking authentication middleware, fully open CORS, and direct MySQL exposure. The backend appeared impaired by a database failure at the time of analysis, likely rendering that C2 temporarily inert.
The content also places Hook in the broader Android banking-malware ecosystem. It is cited as a leading Android malware family in 2024 and 2026 reporting, and as part of a wave of Android bankers using overlay-based credential theft, Accessibility abuse, and remote-control features. Recorded Future observed thousands of malicious files with antivirus signature names such as Hydra, Hook, and Sova every quarter. ThreatFox historical data linked Hook activity to port 9679 on Oracle Cloud IP 143.47.53.106 on 2026-02-05, and another report noted a dark-web rental offering for a Hook Android botnet at $5,000 per month, advertised as compatible with the latest Android versions and offered with a free beta test.
High-confidence indicators and infrastructure mentioned in the content include the Hook C2 IP 31.57.216.126, the hardcoded Socket.IO URL http://31.57.216.126:3434/, and historical ThreatFox linkage to 143.47.53.106 on port 9679.
Reported operators
Threat actors
2 named in public reporting...two Android-based malware families advertised by threat actor DukeEugene, known as Hook and ERMAC.
MITRE ATT&CK
HOOK in ATT&CK
5 distinct techniquesReporting
Research mentioning HOOK
New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds
It's 137 commands outnumber the 107 Zimperium counted in the HOOK trojan, and the playbook is the same one running through a wave of 2026 Android bankers.
XWorm Meets Multi-RAT: A Single Oracle Cloud VPS Running DCRat, Hook, and XWorm Behind LocaltoNet Tunnels - Breakglass Intelligence - Breakglass Intelligence
ThreatFox historical data reveals this IP has been running multiple RAT families simultaneously, each on a different port: ... 2026-02-05 Hook (Android banking trojan) 9679
Dissecting a Live Hook Android Banking Trojan C2: Architecture, Exploitation Surface, and What the Operator Got Wrong - Breakglass Intelligence - Breakglass Intelligence
Hook descends from the ERMAC malware family and represents one of the most capable Android banking trojans in active circulation. It combines traditional overlay injection attacks with VNC-based remote control, giving operators hands-on-keyboard access to victim devices.
AI Development & Software Engineering | CloudATG
HOOK Android Trojan Adds Ransomware Overlays, Expands to 107 Remote Commands
Own Goal? Piracy as an Attack Vector to Target Football Fans
Command-and-Control (C2) panel of the Hook banking malware
Fresh Facebook Data Sale, MonoLock Ransomware, and SIM-Swap Recruitment Announced in Underground Forums
SOCRadar Dark Web Team detected an alleged rental offering for a Hook Android botnet at $5,000 per month. The threat actor claims the malware is an original, fully updated Hook botnet compatible with the latest Android versions and offers a free beta test as proof.
Exposing Crocodilus: New Device Takeover Malware Targeting Android Devices
The mobile threat landscape has been shaped over the years by well-established banking Trojan families such as Anatsa, Octo, Hook...
2024 Malicious Infrastructure Report
Android remained the primary target for mobile malware, with Hook leading.