ERMAC V3.0 Banking Trojan: Full Source Code Leak and Infrastructure Analysis
ID: c55947eb-3510-5848-835a-e354eeb66d2b
STIX ID: report--c55947eb-3510-5848-835a-e354eeb66d2b
Feed Name: Hunt.io Blog
Threat Score
Hunt.io obtained the full ERMAC 3.0 source code and provides a comprehensive analysis of an active Malware-as-a-Service banking trojan, detailing its Laravel backend, React panel, Golang exfiltration server, Android backdoor/builder, over 700 targeted apps, operational commands, MITRE ATT&CK mappings, live infrastructure IOCs, and exploitable weaknesses (hardcoded JWT, default credentials, open registration) that defenders can use to detect and disrupt campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
