Hook

First seen
2023-01-01 00:00:00
Malware type
rat, trojan
Family
Malware family
Last IoC activity
2026-07-22 04:11:15
Profile updated
2026-07-07 14:05:22

Targeted industries: financial-services

Context

According to ThreatFabric, this is a malware family based on apk.ermac. The name hook is the self-advertised named by its vendor DukeEugene. It provides WebSocket communication and has RAT capabilities.

Reports & references

  • spamhaus.org — Botnet Threat Update January To June 2025 (report)
  • info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — Jan Jun%202024%20Botnet%20Threat%20Update (report)
  • research.nccgroup.com — From Ermac To Hook Investigating The Technical Differences Between Two Android Malware Variants (report)
  • info.spamhaus.com — Q4%202023%20Botnet%20Threat%20Update (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Hook (report)
  • sciencedirect.com — S266628172400088X (report)
  • zimperium.com — Hook Version 3 The Banking Trojan With The Most Advanced Capabilities (report)
  • threatfabric.com — Hook A New Ermac Fork With Rat Capabilities (report)
  • cebrf.knf.gov.pl — 858 Hookbot A New Mobile Malware (report)
  • github.com — Hookbot Source (report)
  • medium.com — Hostinghunter Series Chang Way Technologies Co Limited A9Ba4Fce0F65 (report)

External references