logo

From ERMAC to Hook: Investigating the technical differences between two Android malware variants

ID: 41a173df-d785-56b7-8905-8f5d547a6a12

STIX ID: report--41a173df-d785-56b7-8905-8f5d547a6a12

Feed Name: Fox-IT blog

Threat Score
72/100

Date Published: 2023-09-11

Date Updated: 2026-04-27

Author: Global Threat Intelligence

...
...

**Executive summary:** This technical analysis shows that the Hook Android malware is derived from ERMAC and significantly extends its capabilities — adding screen streaming and remote UI control, front-camera photo capture, session cookie theft, expanded crypto seed-stealing support, enhanced Device Admin and accessibility-service abuse, and both WebSocket and HTTP C2 channels — and includes sample SHA-256 hashes, a list of C2 IPs, command enumerations, and detection artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.