← Back to list

Inside the ERMAC Android Banking Trojan’s Exposed Source Code

Every so often, a breach in the cybercriminal ecosystem gives the security world a rare glimpse into how attackers actually operate. In…

Deven Chhajed in DevSecOps & AI · 2025-09-24 03:31 · 0 claps · 3.9 min read
#ermac #android-malware #banking-trojan #source-code-leak #malwareasaservice
Open on Medium ↗
Wiki topics: ECO · Economy · General 🔒 · Cybersecurity

Inside the ERMAC Android Banking Trojan’s Exposed Source Code

Every so often, a breach in the cybercriminal ecosystem gives the security world a rare glimpse into how attackers actually operate. In March 2024, researchers at Hunt.io discovered just such a crack: an open directory containing the full source code for ERMAC v3.0, one of the most notorious Android banking trojans in circulation.

The leak is more than an isolated incident. It is a case study in how professionalized malware-as-a-service (MaaS) platforms are built, run and sometimes, undone by their operators own mistakes.

ERMAC’s Origins and Rise

ERMAC is not a standalone invention. Its lineage traces back through the darker corners of Android malware history:

  • Cerberus: A powerful banking trojan whose leaked code became a seed for successors.
  • BlackRock: An offshoot of Cerberus, operated by the same threat actor now linked to ERMAC.
  • ERMAC (2021): First documented by ThreatFabric, positioned as a MaaS platform available for rent.
  • ERMAC v2.0 (2022): Detected by ESET, advertised for $5,000/month, and targeting 467 apps.
  • Hook (2023): Another malware promoted by the same actor, considered an ERMAC derivative.
  • ERMAC v3.0 (2024): The leaked version, boasting an expanded arsenal and targeting 700+ apps.

This steady evolution shows how one leak often fuels the next generation of threats.

What Was Inside Ermac 3.0.zip

The archive found by Hunt.io was not just a malware sample. It contained the entire ecosystem needed to run ERMAC as a commercial service:

  • Backend Command-and-Control (C2): A PHP system responsible for issuing commands and storing stolen data.
  • Frontend Operator Panel: A React-based dashboard that cybercriminals used to manage campaigns and victims.
  • Exfiltration Server: Written in Go, designed to handle stolen information efficiently.
  • Android Backdoor (Trojan): The malicious APK, written in Kotlin, deployed on victims devices.
  • Builder and Obfuscator: Tools to generate trojanized APKs tailored for campaigns and to disguise them from detection.
  • Deployment Configurations: Scripts and settings for rolling out infrastructure at scale.

This was effectively a turnkey criminal platform: plug it in and an operator could run a global malware campaign.

Exposed ERMAC C2 servers [Source: Hunt.io]

Exposed ERMAC C2 servers [Source: Hunt.io]

Capabilities of ERMAC v3.0

The leak revealed just how powerful the third iteration of ERMAC had become.

-> Target Expansion

ERMAC v3.0 targets more than 700 apps — up from 467 in v2.0 — including banks, shopping platforms and cryptocurrency wallets.

-> Information Theft

  • SMS and Contacts: Intercepts and exfiltrates messages and address book data.
  • Gmail: Extracts email subjects and message content, giving attackers access to sensitive communications like password resets.
  • Files: Offers list and download commands to browse and pull files directly from a device.

-> Device Control

  • Send SMS or forward calls to redirect communications.
  • Launch, uninstall or clear cache of apps remotely.
  • Display fake push notifications to trick users.
  • Activate the front-facing camera to capture photos.
  • Remotely uninstall itself via a “killme” command for evasion.

-> Communications Security

All traffic between the malware and its servers is encrypted using AES-CBC, complicating efforts to intercept or analyze its activity.

-> Attack Technique: Form Injections

ERMAC relies heavily on overlay attacks — displaying fake login pages on top of legitimate apps. Users who enter credentials unknowingly hand them directly to attackers.

One of ERMAC’s form injections [Source: Hunt.io]

One of ERMAC’s form injections [Source: Hunt.io]

Operator Failures

Despite its sophistication, ERMAC’s infrastructure was riddled with basic security mistakes:

  • Hardcoded Credentials: JWT tokens and admin bearer tokens were embedded directly in the code.
  • Default Root Passwords: Weak authentication left doors wide open.
  • No Registration Controls: The admin panel allowed anyone to register via the API.
  • Operational Fingerprints: Unique panel names, HTTP headers and package identifiers exposed their servers to discovery.

By running SQL queries against these clues, Hunt.io analysts were able to map live ERMAC infrastructure, including command-and-control endpoints, exfiltration servers and builder panels.

In the end, the criminals own negligence made their platform far easier to track.

Accessing the ERMAC panel [Source: Hunt.io]

Accessing the ERMAC panel [Source: Hunt.io]

The Double-Edged Impact of the Leak

Leaks of this kind always cut both ways:

  • Defensive Advantage: Security vendors now have direct insight into ERMAC’s architecture and methods, enabling stronger detection and mitigation.
  • Criminal Setback: The operators credibility takes a hit. Customers renting ERMAC may lose trust in its secrecy and effectiveness.
  • Future Risk: The source code is now public. Other threat actors could modify and repurpose it into new variants, potentially more resilient and harder to detect.

History shows this pattern well: Cerberus begat BlackRock, which led to ERMAC. The cycle of adaptation rarely stops.

Conclusion

The ERMAC v3.0 source code leak exposes more than malware — it exposes the inner workings of the cybercrime economy. For defenders, it is an invaluable opportunity to study, detect and disrupt. For operators, it is a stark lesson in how poor security practices can undo even the most sophisticated platforms.

As history shows with Cerberus and BlackRock, one leak often seeds the next generation of threats. The same could prove true here. What is certain, however, is that awareness and proactive defense remain the strongest shields against an evolving adversary.

Stay One Step Ahead of Cybercriminals!

🔹 The best defense is staying informed and proactive!

🔹 Follow me for more insights on the latest cyber threats, attack trends and security best practices.

🔗 Let’s **connect **and fortify our digital world together!


메타데이터
post_id
be894d1ece3c
slug
inside-the-ermac-android-banking-trojans-exposed-source-code-be894d1ece3c
url
https://medium.com/devsecops-ai/inside-the-ermac-android-banking-trojans-exposed-source-code-be894d1ece3c
canonical_url
https://medium.com/devsecops-ai/inside-the-ermac-android-banking-trojans-exposed-source-code-be894d1ece3c
author_url
https://medium.com/@devenchhajed24
status
ok
fetched_at
2026-08-09 14:06:39