Ermac

Malware updated 9 months ago (2024-11-29T13:57:27.259Z)
Download STIX
Preview STIX
ERMAC is a malicious software (malware) that was first observed in 2021 as a banking trojan. It targets over 450 financial and social media applications, with its core features designed to send SMS messages, display phishing windows on top of legitimate apps, extract lists of installed applications, gather SMS messages, and siphon recovery seed phrases for multiple cryptocurrency wallets. ERMAC was built on the Cerberus codebase, and later identified as a predecessor to another malware called Hook. Despite some modifications introduced by ERMAC and Alien, it shares many similarities with other malwares derived from the same source code. In January 2023, ThreatFabric documented Hook, describing it as an "ERMAC fork" offered for sale on underground forums for $7,000 per month. A subsequent analysis revealed that Hook is indeed based on ERMAC, with both sharing nearly identical implementations for the 30 commands that a malware operator can send to an infected device. The majority of their command-and-control (C2) servers are located in Russia, followed by the Netherlands, the UK, the US, Germany, France, Korea, and Japan. Despite some differences between ERMAC and Hook, they both have the ability to log keystrokes and exploit Android's accessibility services to conduct overlay attacks. These attacks allow the malware to display content over other apps, enabling them to steal credentials from over 700 different apps. In a technical analysis published last week, NCC Group security researchers Joshua Kamp and Alberto Segura confirmed that the ERMAC source code was used as a base for Hook.
Description last updated: 2024-10-17T12:36:59.871Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Cerberus is a possible alias for Ermac. Cerberus is a potent Android banking trojan that first surfaced on underground marketplaces in 2019. This malicious software, which operates as a hidden application on the victim's device, infiltrates systems via suspicious downloads, emails, or websites without the user's awareness. Once inside, it
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Trojan
Malware
Android
Banking
Source
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Ermac Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more