Hook
- First seen
- 2023-01-01 00:00:00
- Malware type
- rat, trojan
- Family
- Malware family
- Last IoC activity
- 2026-07-22 04:11:15
- Profile updated
- 2026-07-07 14:05:22
Targeted industries: financial-services
Context
According to ThreatFabric, this is a malware family based on apk.ermac. The name hook is the self-advertised named by its vendor DukeEugene. It provides WebSocket communication and has RAT capabilities.
Reports & references
- spamhaus.org — Botnet Threat Update January To June 2025 (report)
- info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — Jan Jun%202024%20Botnet%20Threat%20Update (report)
- research.nccgroup.com — From Ermac To Hook Investigating The Technical Differences Between Two Android Malware Variants (report)
- info.spamhaus.com — Q4%202023%20Botnet%20Threat%20Update (report)
- malpedia.caad.fkie.fraunhofer.de — Apk.Hook (report)
- sciencedirect.com — S266628172400088X (report)
- zimperium.com — Hook Version 3 The Banking Trojan With The Most Advanced Capabilities (report)
- threatfabric.com — Hook A New Ermac Fork With Rat Capabilities (report)
- cebrf.knf.gov.pl — 858 Hookbot A New Mobile Malware (report)
- github.com — Hookbot Source (report)
- medium.com — Hostinghunter Series Chang Way Technologies Co Limited A9Ba4Fce0F65 (report)