ERMAC Malware Back In Action: New Threats And Attack Methods
ID: 6376d1dd-03e2-5fbb-8e4b-a0f272fa5c5d
STIX ID: report--6376d1dd-03e2-5fbb-8e4b-a0f272fa5c5d
Feed Name: Cyble Blog
Threat Score
Cyble Research Labs details ERMAC 2.0, an Android banking trojan rented on underground forums that targets hundreds of applications (reported 467), spreads via fake Bolt Food and browser-update sites, abuses Accessibility and overlay permissions to inject phishing pages, exfiltrates credentials to C2 servers, and includes APK metadata, manifest and code analysis, MITRE technique mappings, IOCs (file hashes, distribution URLs, C2 IPs), and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
