In the first case, we observed Brunhilda posing as a QR code creator app, Brunhilda dropped samples from established families, like Hydra, as well as novel ones, like Ermac.
Hydra
Hydra is an Android banking trojan focused on credential theft and fraud against mobile banking, payment, and cryptocurrency users.
Profile source: Mallory opens in a new tabHydra
Family profile
Hydra is an Android banking trojan focused on credential theft and fraud against mobile banking, payment, and cryptocurrency users. It is known for overlay-based phishing against targeted applications, abuse of Android Accessibility Services to automate malicious actions and resist removal, interception of SMS messages and one-time passwords, theft of cookies and other device data, and support for broader post-compromise actions such as contact harvesting, notification interception, call-forwarding manipulation, USSD abuse, and bulk SMS propagation. Multiple analyses have shown Hydra using packing and dynamic code-loading techniques, including DexClassLoader-based payload loading, anti-emulation checks, obfuscated strings, and staged payload extraction from embedded resources, all of which complicate analysis and detection.
Hydra has repeatedly been distributed through staged Android infection chains rather than overtly malicious first-stage apps. Observed delivery methods include trojanized applications on Google Play posing as utilities such as document scanners, QR-related tools, and other benign-looking apps; fake update prompts that trick users into sideloading a second-stage payload; phishing sites; and third-party droppers such as Brunhilda and DawDropper. Campaigns have selectively targeted users by geography and installed-app profiling, and Hydra activity has been reported against banking users in regions including Turkey, Colombia, Europe, and the United States.
Operationally, Hydra is part of the broader Android banking-malware ecosystem alongside families such as Anubis, Cerberus, Ermac, Octo, and SharkBot. It supports webinject and overlay workflows used to impersonate legitimate financial and other applications, enabling theft of credentials, session material, and authentication data that can be used for account takeover and fraudulent transactions. Hydra has also been referenced as a base or inspiration for bespoke Android malware used in targeted operations, underscoring its adaptability beyond commodity banking fraud. Overall, Hydra is a mature Android bankbot family characterized by staged delivery, strong anti-analysis measures, and a blend of credential theft, session abuse, and device-level control features tailored for mobile financial fraud.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Keylogging
- Persistence
- Post Exploitation
- Session Hijacking
Reported operators
Threat actors
3 named in public reportingMITRE ATT&CK
Hydra in ATT&CK
45 distinct techniquesTechniques
45 techniquesReporting
Research mentioning Hydra
Threat news: TeamTNT stealing credentials using EC2 Instance Metadata | Sysdig
TeamTNT continued to evolve from a Linux-focused cryptojacking group into a broad cloud threat actor targeting exposed Redis, Docker, Kubernetes, Jupyter, Hadoop, PostgreSQL, Tomcat, Nginx, SSH, and other internet-facing services. Researchers tied the group to worm-like campaigns that rapidly scanned for vulnerable hosts, deployed XMRig miners, dropped Tsunami-based IRC bots including DDoS-capable variants, and used malicious container images on Docker Hub to spread payloads at scale. One TeamTNT-linked Docker Hub account reportedly served images pulled more than 150,000 times, while later campaigns showed the group abusing public registries, compromised accounts, and cloud-native tooling to infect newly exposed systems and report them back to command-and-control infrastructure. Across these operations, TeamTNT consistently paired monetization with aggressive credential theft and stealth. Investigations found the group harvesting AWS, Azure, GCP, Kubernetes, Git, NPM, Grafana, database, and storage secrets; stealing SSH keys and host data; and using tools such as Weave Scope, Peirates, BotB, MimiPenguin, Mimipy, tmate, and Gsocket to expand access and persistence. Analysts also documented detection evasion through log wiping, process hiding, LD_PRELOAD userland rootkits, the Diamorphine kernel rootkit, privileged containers with restart policies, and even disabling runc to lock out rival attackers, underscoring TeamTNT’s shift from opportunistic mining to sustained compromise of cloud and container environments.
Matrix - Enterprise - Containers | MITRE ATT&CK®
Abusing Legitimate Cloud Monitoring Tools for Cyber Attacks - Intezer
TeamTNT Cryptomining Explosion 🧨 - Intezer
ERMAC 2.0: Perfecting the Art of Account Takeover | Intel 471
ERMAC evolved into a more capable Android banking trojan that abuses Accessibility Services to steal credentials, intercept SMS codes, and capture Google authentication tokens, allowing attackers to bypass multi-factor authentication and take over banking, financial, ecommerce, and cryptocurrency accounts. Researchers said ERMAC 2.0, derived from leaked Cerberus code and sold through the malware-as-a-service ecosystem, expanded its targeting from 378 applications to 467 and used encrypted communications, phishing overlays, and app-list reconnaissance to fetch tailored injection content from command-and-control servers. The malware was distributed through fake browser update pages, phishing sites impersonating brands such as Bolt Food, trojanized Android apps, and Google Play dropper applications that helped infect more than 300,000 devices across multiple banking trojan campaigns. ThreatFabric also linked ERMAC delivery to the Zombinder app-binding service, which hides malicious payloads inside working Android apps, and observed overlapping infrastructure that also pushed Windows malware including Erbium Stealer, Laplas Clipper, and Aurora Stealer, underscoring a broader criminal ecosystem built around outsourced obfuscation, staging, and malware delivery.