logo

ERMAC Android malware source code leak exposes banking trojan infrastructure

ID: 40a6653d-ba87-580b-b7a2-774eb877e0aa

STIX ID: report--40a6653d-ba87-580b-b7a2-774eb877e0aa

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-08-18

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

ERMAC v3 — an Android banking trojan sold as malware-as-a-service — had its full source code and associated infrastructure exposed in an open directory; researchers found backend/frontend code, exfiltration servers, a builder, and configuration files. The leak reveals expanded targeting (over 700 apps), advanced data-theft and device-control features (SMS, contacts, Gmail, form injections, camera, remote uninstall), and operator OPSEC failures (hardcoded tokens, default creds, unprotected admin panels) that both degrade the operators' service and may enable other actors to produce modified, harder-to-detect variants.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.