logo

What the ERMAC Source Leak Says About HookBot

ID: 601642ff-aa98-5930-91e0-39b01c351d0c

STIX ID: report--601642ff-aa98-5930-91e0-39b01c351d0c

Feed Name: Censys Blog

Threat Score
75/100

Date Published: 2026-08-25

Date Updated: 2026-08-26

...
...

This report analyzes ERMAC and HookBot, two closely related Android banking trojans that forked from Cerberus and whose Laravel/React panel and builder source leaked; the leak allowed many operators to stand up panels, increasing short-term activity. The analysis covers code lineage and shared artifacts, attack mechanics (accessibility-based overlays, credential and 2FA theft), the builder and default configuration left in leaked code, panel and builder ports, detection artifacts (favicons, builder obfuscator flags, PROTECTED AREA gate on :50000), observed infrastructure and IoCs (domains, IPs, APK SHA-256s), and operational mitigations like an IP-whitelist security gate and Telegram bot integration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.