ERMAC

Malware type
trojan, credential-stealer
Family
Malware family
Last IoC activity
2026-07-22 00:36:45
Profile updated
2026-07-07 14:03:29

Targeted industries: financial-services

Context

According to Intel471, ERMAC, an Android banking trojan enables bad actors to determine when certain apps are launched and then overwrites the screen display to steal the user's credentials

Reports & references

  • resecurity.com — In The Box Mobile Malware Webinjects Marketplace (report)
  • threatfabric.com — Ermac Another Cerberus Reborn (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Ermac (report)
  • intel471.com — Rmac 2 0 Perfecting The Art Of Account Takeover (report)
  • hunt.io — Ermac V3 Banking Trojan Source Code Leak (report)
  • research.nccgroup.com — From Ermac To Hook Investigating The Technical Differences Between Two Android Malware Variants (report)
  • twitter.com — 1709096404835356883 (report)
  • linkedin.com — Threatmon Rising Threat Ermac Variant Activity 7305193522180071426 J8C5 (report)
  • blog.cyble.com — Ermac Back In Action (report)
  • twitter.com — 1445618031464357888 (report)
  • threatfabric.com — Zombinder Ermac And Desktop Stealers (report)

External references