ERMAC
- Malware type
- trojan, credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:36:45
- Profile updated
- 2026-07-07 14:03:29
Targeted industries: financial-services
Context
According to Intel471, ERMAC, an Android banking trojan enables bad actors to determine when certain apps are launched and then overwrites the screen display to steal the user's credentials
Reports & references
- resecurity.com — In The Box Mobile Malware Webinjects Marketplace (report)
- threatfabric.com — Ermac Another Cerberus Reborn (report)
- malpedia.caad.fkie.fraunhofer.de — Apk.Ermac (report)
- intel471.com — Rmac 2 0 Perfecting The Art Of Account Takeover (report)
- hunt.io — Ermac V3 Banking Trojan Source Code Leak (report)
- research.nccgroup.com — From Ermac To Hook Investigating The Technical Differences Between Two Android Malware Variants (report)
- twitter.com — 1709096404835356883 (report)
- linkedin.com — Threatmon Rising Threat Ermac Variant Activity 7305193522180071426 J8C5 (report)
- blog.cyble.com — Ermac Back In Action (report)
- twitter.com — 1445618031464357888 (report)
- threatfabric.com — Zombinder Ermac And Desktop Stealers (report)