Skip to content

Hydra

Hydra is an Android banking trojan focused on credential theft and fraud against mobile banking, payment, and cryptocurrency users.

Profile source: Mallory opens in a new tab

Hydra

Family profile

Hydra is an Android banking trojan focused on credential theft and fraud against mobile banking, payment, and cryptocurrency users. It is known for overlay-based phishing against targeted applications, abuse of Android Accessibility Services to automate malicious actions and resist removal, interception of SMS messages and one-time passwords, theft of cookies and other device data, and support for broader post-compromise actions such as contact harvesting, notification interception, call-forwarding manipulation, USSD abuse, and bulk SMS propagation. Multiple analyses have shown Hydra using packing and dynamic code-loading techniques, including DexClassLoader-based payload loading, anti-emulation checks, obfuscated strings, and staged payload extraction from embedded resources, all of which complicate analysis and detection.

Hydra has repeatedly been distributed through staged Android infection chains rather than overtly malicious first-stage apps. Observed delivery methods include trojanized applications on Google Play posing as utilities such as document scanners, QR-related tools, and other benign-looking apps; fake update prompts that trick users into sideloading a second-stage payload; phishing sites; and third-party droppers such as Brunhilda and DawDropper. Campaigns have selectively targeted users by geography and installed-app profiling, and Hydra activity has been reported against banking users in regions including Turkey, Colombia, Europe, and the United States.

Operationally, Hydra is part of the broader Android banking-malware ecosystem alongside families such as Anubis, Cerberus, Ermac, Octo, and SharkBot. It supports webinject and overlay workflows used to impersonate legitimate financial and other applications, enabling theft of credentials, session material, and authentication data that can be used for account takeover and fraudulent transactions. Hydra has also been referenced as a base or inspiration for bespoke Android malware used in targeted operations, underscoring its adaptability beyond commodity banking fraud. Overall, Hydra is a mature Android bankbot family characterized by staged delivery, strong anti-analysis measures, and a blend of credential theft, session abuse, and device-level control features tailored for mobile financial fraud.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Session Hijacking

Reported operators

Threat actors

3 named in public reporting
Brunhilda

In the first case, we observed Brunhilda posing as a QR code creator app, Brunhilda dropped samples from established families, like Hydra, as well as novel ones, like Ermac.

UAC-0149

"...GREYBATTLE, a bespoke version of the Hydra banking trojan..."

UNC5125

"...GREYBATTLE, a bespoke version of the Hydra banking trojan..."

MITRE ATT&CK

Hydra in ATT&CK

45 distinct techniques

Reporting

Research mentioning Hydra

Jul 31
Sysdig

Threat news: TeamTNT stealing credentials using EC2 Instance Metadata | Sysdig

TeamTNT continued to evolve from a Linux-focused cryptojacking group into a broad cloud threat actor targeting exposed Redis, Docker, Kubernetes, Jupyter, Hadoop, PostgreSQL, Tomcat, Nginx, SSH, and other internet-facing services. Researchers tied the group to worm-like campaigns that rapidly scanned for vulnerable hosts, deployed XMRig miners, dropped Tsunami-based IRC bots including DDoS-capable variants, and used malicious container images on Docker Hub to spread payloads at scale. One TeamTNT-linked Docker Hub account reportedly served images pulled more than 150,000 times, while later campaigns showed the group abusing public registries, compromised accounts, and cloud-native tooling to infect newly exposed systems and report them back to command-and-control infrastructure. Across these operations, TeamTNT consistently paired monetization with aggressive credential theft and stealth. Investigations found the group harvesting AWS, Azure, GCP, Kubernetes, Git, NPM, Grafana, database, and storage secrets; stealing SSH keys and host data; and using tools such as Weave Scope, Peirates, BotB, MimiPenguin, Mimipy, tmate, and Gsocket to expand access and persistence. Analysts also documented detection evasion through log wiping, process hiding, LD_PRELOAD userland rootkits, the Diamorphine kernel rootkit, privileged containers with restart policies, and even disabling runc to lock out rival attackers, underscoring TeamTNT’s shift from opportunistic mining to sustained compromise of cloud and container environments.

Apr 14
Mitre Attack Website

Matrix - Enterprise - Containers | MITRE ATT&CK®

Jan 1
Intezer

Abusing Legitimate Cloud Monitoring Tools for Cyber Attacks - Intezer

Jan 1
Intezer

TeamTNT Cryptomining Explosion 🧨 - Intezer

Jan 1
Intel471

ERMAC 2.0: Perfecting the Art of Account Takeover | Intel 471

ERMAC evolved into a more capable Android banking trojan that abuses Accessibility Services to steal credentials, intercept SMS codes, and capture Google authentication tokens, allowing attackers to bypass multi-factor authentication and take over banking, financial, ecommerce, and cryptocurrency accounts. Researchers said ERMAC 2.0, derived from leaked Cerberus code and sold through the malware-as-a-service ecosystem, expanded its targeting from 378 applications to 467 and used encrypted communications, phishing overlays, and app-list reconnaissance to fetch tailored injection content from command-and-control servers. The malware was distributed through fake browser update pages, phishing sites impersonating brands such as Bolt Food, trojanized Android apps, and Google Play dropper applications that helped infect more than 300,000 devices across multiple banking trojan campaigns. ThreatFabric also linked ERMAC delivery to the Zombinder app-binding service, which hides malicious payloads inside working Android apps, and observed overlapping infrastructure that also pushed Windows malware including Erbium Stealer, Laplas Clipper, and Aurora Stealer, underscoring a broader criminal ecosystem built around outsourced obfuscation, staging, and malware delivery.

Sep 11
Group Ib

Storm clouds on the horizon: Resurgence of TeamTNT? | Group-IB Blog

Jul 13
Aquasec Other

TeamTNT Reemerged with New Aggressive Cloud Campaign

Dec 8
Threatfabric

Zombinder: new obfuscation service used by Ermac, now distributed next to desktop stealers

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.