DukeEugene is a cybercriminal actor associated with the advertising and distribution of Android banking malware, notably ERMAC and Hook. The actor is known in criminal-market contexts for promoting these malware families, with Hook presented as a successor or derivative of ERMAC. Technical analysis has concluded that Hook was built on ERMAC source code while substantially extending its functionality. The malware associated with DukeEugene is designed for post-compromise control of Android devices and supports a broad range of credential and financial theft activity. Reported capabilities include theft of Google login cookies, theft of cryptocurrency wallet recovery seeds, screen streaming, and covert image capture through the device’s front-facing camera. These features indicate a focus on credential theft, session hijacking, surveillance of infected devices, and theft of digital assets. The overlap between ERMAC and Hook, combined with Hook’s expanded command set, suggests iterative malware development aimed at improving post-exploitation and data-theft capabilities on mobile platforms. DukeEugene is best characterized as a financially motivated cybercriminal actor involved in the Android malware ecosystem rather than a nation-state operator. High-confidence public reporting directly ties the actor to the promotion of Hook and ERMAC, but does not firmly establish broader attribution, geographic origin, or a defined victimology by country or industry.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.