Skip to content

Reporting

Research mentioning Laplas

Jan 1
Intel471

ERMAC 2.0: Perfecting the Art of Account Takeover | Intel 471

ERMAC evolved into a more capable Android banking trojan that abuses Accessibility Services to steal credentials, intercept SMS codes, and capture Google authentication tokens, allowing attackers to bypass multi-factor authentication and take over banking, financial, ecommerce, and cryptocurrency accounts. Researchers said ERMAC 2.0, derived from leaked Cerberus code and sold through the malware-as-a-service ecosystem, expanded its targeting from 378 applications to 467 and used encrypted communications, phishing overlays, and app-list reconnaissance to fetch tailored injection content from command-and-control servers. The malware was distributed through fake browser update pages, phishing sites impersonating brands such as Bolt Food, trojanized Android apps, and Google Play dropper applications that helped infect more than 300,000 devices across multiple banking trojan campaigns. ThreatFabric also linked ERMAC delivery to the Zombinder app-binding service, which hides malicious payloads inside working Android apps, and observed overlapping infrastructure that also pushed Windows malware including Erbium Stealer, Laplas Clipper, and Aurora Stealer, underscoring a broader criminal ecosystem built around outsourced obfuscation, staging, and malware delivery.

Dec 8
Threatfabric

Zombinder: new obfuscation service used by Ermac, now distributed next to desktop stealers

May 25
Cyble Blog Historic

ERMAC Malware Back In Action: New Threats And Attack Methods

Nov 17
Threatfabric

Deceive the Heavens to Cross the sea

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.