logo

Cyble ERMAC Android Malware Increasingly Active

ID: 2ba5318d-5066-5d0b-8f6e-215ced55fb9d

STIX ID: report--2ba5318d-5066-5d0b-8f6e-215ced55fb9d

Feed Name: Cyble Blog

Threat Score
72/100

Date Published: 2025-11-26

Date Updated: 2026-07-16

...
...

Cyble Research & Intelligence Labs identified a widespread phishing campaign distributing the ERMAC Android banking trojan via typosquatted and fake app-store pages (masquerading as Google Wallet, PayPal, Snapchat, VidMate and others). The malware steals contacts, SMS and the list of installed apps, uses phishing overlays to harvest credentials, communicates with a C2/admin panel, and the report includes multiple IOCs (file hashes, phishing URLs, and IPs) and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.