ERMAC evolved into a more capable Android banking trojan that abuses Accessibility Services to steal credentials, intercept SMS codes, and capture Google authentication tokens, allowing attackers to bypass multi-factor authentication and take over banking, financial, ecommerce, and cryptocurrency accounts. Researchers said ERMAC 2.0, derived from leaked Cerberus code and sold through the malware-as-a-service ecosystem, expanded its targeting from 378 applications to 467 and used encrypted communications, phishing overlays, and app-list reconnaissance to fetch tailored injection content from command-and-control servers.
The malware was distributed through fake browser update pages, phishing sites impersonating brands such as Bolt Food, trojanized Android apps, and Google Play dropper applications that helped infect more than 300,000 devices across multiple banking trojan campaigns. ThreatFabric also linked ERMAC delivery to the Zombinder app-binding service, which hides malicious payloads inside working Android apps, and observed overlapping infrastructure that also pushed Windows malware including Erbium Stealer, Laplas Clipper, and Aurora Stealer, underscoring a broader criminal ecosystem built around outsourced obfuscation, staging, and malware delivery.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
ThreatFabric reported that the same infrastructure distributing Ermac also offered Windows malware through a 'Download for Windows' option. The Windows chain delivered Erbium Stealer, Aurora Stealer, and Laplas Clipper, and ThreatFabric observed more than 1,300 Erbium victims.
ThreatFabric analyzed a campaign using the Android payload-binding service it named Zombinder to distribute Ermac through fake websites and trojanized legitimate apps. The modified apps remained functional while covertly prompting victims to install malware.
ThreatFabric identified the Brunhilda group as distributing Ermac and Hydra through trojanized apps on Google Play, including a QR code creator app. The droppers registered devices with command-and-control infrastructure and then downloaded payload packages after profiling victims.
ERMAC was first discovered in late August 2021 as an Android banking trojan targeting Polish users. It was built from leaked Cerberus malware code and initially supported credential theft from hundreds of applications.
In 2021, ThreatFabric reported that Google Play dropper campaigns distributing Ermac, Anatsa, Alien, and Hydra infected more than 300,000 devices over a four-month span. The droppers masqueraded as legitimate apps and used staged delivery to evade review and detection.
Intel 471 described ERMAC as a mature malware-as-a-service operation that abuses Android Accessibility features for overlay attacks and can bypass MFA by stealing Google authentication and SMS tokens. The report also linked ERMAC promotion to DukeEugene and associated some bot infrastructure with Yalishanda bulletproof hosting.
Cyble Research Labs reported that ERMAC 2.0 was being rented on underground forums for $5,000 per month and delivered through fake websites, including a Bolt Food lure and fake browser update pages. The report said version 2.0 expanded targeting from 378 applications in ERMAC 1.0 to 467 applications.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 178 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
intel471.com
Open sourcethreatfabric.com
Open sourceblog.cyble.com
Open sourcethreatfabric.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.