Reporting
Research mentioning Laplas
ERMAC 2.0: Perfecting the Art of Account Takeover | Intel 471
ERMAC evolved into a more capable Android banking trojan that abuses Accessibility Services to steal credentials, intercept SMS codes, and capture Google authentication tokens, allowing attackers to bypass multi-factor authentication and take over banking, financial, ecommerce, and cryptocurrency accounts. Researchers said ERMAC 2.0, derived from leaked Cerberus code and sold through the malware-as-a-service ecosystem, expanded its targeting from 378 applications to 467 and used encrypted communications, phishing overlays, and app-list reconnaissance to fetch tailored injection content from command-and-control servers. The malware was distributed through fake browser update pages, phishing sites impersonating brands such as Bolt Food, trojanized Android apps, and Google Play dropper applications that helped infect more than 300,000 devices across multiple banking trojan campaigns. ThreatFabric also linked ERMAC delivery to the Zombinder app-binding service, which hides malicious payloads inside working Android apps, and observed overlapping infrastructure that also pushed Windows malware including Erbium Stealer, Laplas Clipper, and Aurora Stealer, underscoring a broader criminal ecosystem built around outsourced obfuscation, staging, and malware delivery.