trojan – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Tue, 19 Aug 2025 02:29:15 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 trojan – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 ERMAC Android malware source code leak exposes banking trojan infrastructure https://earlybirdsinvest.com/ermac-android-malware-source-code-leak-exposes-banking-trojan-infrastructure/ https://earlybirdsinvest.com/ermac-android-malware-source-code-leak-exposes-banking-trojan-infrastructure/#respond Tue, 19 Aug 2025 02:29:15 +0000 https://earlybirdsinvest.com/ermac-android-malware-source-code-leak-exposes-banking-trojan-infrastructure/

ERMAC Android malware source code leak exposes banking trojan infrastructure

The source code for version 3 of the ERMAC Android banking trojan has been leaked online, exposing the internals of the malware-as-a-service platform and the operator’s infrastructure.

The code base was discovered in an open directory by Hunt.io researchers while scanning for exposed resources in March 2024.

They located an archive named Ermac 3.0.zip, which contained the malware’s code, including backend, frontend (panel), exfiltration server, deployment configurations, and the trojan’s builder and obfuscator.

The researchers analyzed the code, finding that it significantly expanded the targeting capabilities compared to previous versions, with more than 700 banking, shopping, and cryptocurrency apps.

ERMAC was first documented in September 2021  by ThreatFabric – a provider of online payment fraud solutions and intelligence for the financial services sector, as an evolution of the Cerberus banking trojan operated by a threat actor known as ‘BlackRock.’

ERMAC v2.0 was spotted by ESET in May 2022, rented to cybercriminals for a monthly fee of $5,000, and targeting 467 apps, up from 378 in the previous version.

In January 2023, ThreatFabric observed BlackRock promoting a new Android malware tool named Hook, which appeared to be an evolution of ERMAC.

ERMAC v3.0 capabilities

Hunt.io found and analyzed ERMAC’s PHP command-and-control (C2) backend, React front-end panel, Go-based exfiltration server, Kotlin backdoor, and the builder panel for generating custom trojanized APKs.

According to the researchers, ERMAC v3.0 now targets sensitive user information in more than 700 apps.

One of ERMAC's form injections
One of ERMAC’s form injections
Source: Hunt.io

Additionally, the latest version expands on previously documented form-injection techniques, uses AES-CBC for encrypted communications, features an overhauled operator panel, and enhances data theft and device control.

Specifically, Hunt.io has documented the following capabilities for the latest ERMAC release:

  • Theft of SMS, contacts, and registered accounts
  • Extraction of Gmail subjects and messages
  • File access via ‘list’ and ‘download’ commands
  • SMS sending and call forwarding for communication abuse
  • Photo capturing via the front camera
  • Full app management (launch, uninstall, clear cache)
  • Displaying fake push notifications for deception
  • Uninstalls remotely (killme) for evasion

Infrastructure exposed

Hunt.io analysts used SQL queries to identify live, exposed infrastructure currently used by the threat actors, identifying C2 endpoints, panels, exfiltration servers, and builder deployments.

Exposed ERMAC C2 servers
Exposed ERMAC C2 servers
Source: Hunt.io

Apart from exposing the malware’s source code, the ERMAC operators had several other major opsec failures, including hardcoded JWT tokens, default root credentials, and no registration protections on the admin panel, allowing anyone to access, manipulate, or disrupt ERMAC panels.

Finally, the panel names, headers, package names, and various other operational fingerprints left little doubt about attribution and made discovery and mapping of the infrastructure a lot easier.

Accessing the ERMAC panel
Accessing the ERMAC panel
Source: Hunt.io

The ERMAC V3.0 source code leak weakens the malware operation, first by eroding customer trust in the MaaS in its ability to protect information from law enforcement or allow running campaigns with low detection risk.

Threat detection solutions are also likely to get better at spotting ERMAC. However, if the source code falls into the hands of other threat actors, it is possible to observe in the future modified variants of ERMAC that are more difficult to detect.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/ermac-android-malware-source-code-leak-exposes-banking-trojan-infrastructure/feed/ 0 53931
US Lawmaker sounds alarm on GENIUS bill, says it's a CBDC Trojan Horse https://earlybirdsinvest.com/us-lawmaker-sounds-alarm-on-genius-bill-says-its-a-cbdc-trojan-horse/ https://earlybirdsinvest.com/us-lawmaker-sounds-alarm-on-genius-bill-says-its-a-cbdc-trojan-horse/#respond Sat, 19 Jul 2025 22:24:26 +0000 https://earlybirdsinvest.com/us-lawmaker-sounds-alarm-on-genius-bill-says-its-a-cbdc-trojan-horse/

United States congresswoman Marjorie Taylor Greene said that the GENIUS stablecoin bill creates a “backdoor” for the government to effectively create a central bank digital currency, veiled as privately issued crypto tokens.

The lawmaker said that regulated stablecoins feature “functional surveillance capabilities,” which make them indistinguishable from CBDCs. In a separate social media post, she added: 

“This bill regulates stablecoins and provides for the backdoor central bank digital currency. The Federal Reserve has been planning a CBDC for years, and this will open the door to move you to a cashless society and into digital currency that can be weaponized against you by an authoritarian government controlling your ability to buy and sell.”

Rep. Greene’s comments echo a growing tide of individuals in the Bitcoin and crypto communities sounding the alarm on regulated stablecoins and the potential for these privately-issued tokens to become captured by the state.

US Government, United States, Stablecoin, CBDC
US President Donald Trump signs the GENIUS stablecoin bill into law. Source: The White House

Related: GENIUS Act heads to Trump’s desk: Here’s what will change

The Bitcoin and crypto communities voice the same concerns

“The Genius Act forces stablecoins into CBDC compliance and control; functionally identical to a CBDC, without the scary name,” Bitcoin advocate Justin Bechler wrote in a July 19 X post.

Saifedean Ammous, author of “The Bitcoin Standard,” argued that the US dollar, in any form, is essentially a central bank digital currency that is already monitored by the state and increasingly digital.

“Governments realize that if they control stablecoins, they control financial transactions,” Jean Rausis, co-founder of the Smardex decentralized trading platform, said.

The executive added that the ability to freeze or rollback transactions and surveil centrally-managed stablecoins makes them indistinguishable from a CBDC.

The GENIUS bill was amended in March to include stricter anti-money-laundering provisions, sanctions compliance, and know-your-customer requirements, necessitating financial surveillance and the ability to censor transactions.

In October 2024, Curve Finance founder Dr. Michael Egorov told Cointelegraph that centralized stablecoins carry the risk of regulatory capture, including government seizure of the underlying fiat assets held in bank accounts or custodial institutions backing the digital tokens.

Magazine: Crypto wanted to overthrow banks, now it’s becoming them in stablecoin fight

]]> https://earlybirdsinvest.com/us-lawmaker-sounds-alarm-on-genius-bill-says-its-a-cbdc-trojan-horse/feed/ 0 48598 Triada Trojan Secretly Draining Crypto from Android Devices https://earlybirdsinvest.com/triada-trojan-secretly-draining-crypto-from-android-devices/ https://earlybirdsinvest.com/triada-trojan-secretly-draining-crypto-from-android-devices/#respond Sun, 06 Apr 2025 15:24:41 +0000 https://earlybirdsinvest.com/triada-trojan-secretly-draining-crypto-from-android-devices/

Android smartphones sold online at discounted prices are being shipped with hidden malware that can steal crypto and personal data, according to an April 1 report from the cybersecurity firm Kaspersky.

The malware, known as Triada, allows attackers to access nearly everything on the phone. It can read text messages, gather login details, and change cryptocurrency wallet addresses during transactions. This lets the attackers quietly move funds to their own accounts without the user noticing.

Kaspersky found that around $270,000 of digital assets had already been moved to wallets linked to the attackers. However, this number may be higher, especially since they also targeted Monero
XMR


$212.80

, a type of cryptocurrency that is difficult to trace.

What is Monero? XMR Animated Explainer

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

What makes the threat harder to detect is that the malware is installed before the phone ever reaches the buyer. Some sellers may be unaware that the devices they offer are already compromised. Kaspersky’s experts believe that somewhere along the supply chain—perhaps during production or shipment—the phones are being tampered with.

Over 2,600 infections have been confirmed, mostly in Russia, and all reported within the first three months of 2025. Triada, which has been around since 2016, was initially used to target financial apps and messaging platforms like WhatsApp and Gmail, which often spread through fake apps or misleading links.

According to Dmitry Kalinin from Kaspersky, Triada remains one of the most serious threats to Android users, as it gives attackers ongoing access without the victim realizing it.

On March 28, ThreatFabric, a cybersecurity company, discovered an Android malware called Crocodilus. How does this malware work? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/triada-trojan-secretly-draining-crypto-from-android-devices/feed/ 0 29339
Microsoft uncovers new trojan targeting crypto wallet extensions on chrome https://earlybirdsinvest.com/microsoft-uncovers-new-trojan-targeting-crypto-wallet-extensions-on-chrome/ https://earlybirdsinvest.com/microsoft-uncovers-new-trojan-targeting-crypto-wallet-extensions-on-chrome/#respond Wed, 19 Mar 2025 02:39:43 +0000 https://earlybirdsinvest.com/microsoft-uncovers-new-trojan-targeting-crypto-wallet-extensions-on-chrome/

Microsoft researchers have identified a new remote access trojan (RAT) named StilachiRAT, designed to steal cryptocurrency wallet data, credentials, and system information while maintaining persistent access to compromised devices, the company disclosed on March 17.

The malware, first detected in November 2024, employs stealth techniques and anti-forensic measures to evade detection.

While Microsoft has not yet attributed StilachiRAT to a known threat actor, security experts warn that its capabilities could pose a significant cybersecurity risk, particularly to users handling crypto.

Sophisticated threat

StilachiRAT is capable of scanning for and extracting data from 20 different cryptocurrency wallet extensions in Google Chrome, including MetaMask, Trust Wallet, and Coinbase Wallet, allowing attackers to access stored funds.

Additionally, the malware decrypts saved Chrome passwords, monitors clipboard activity for sensitive financial data, and establishes remote command-and-control (C2) connections via TCP ports 53, 443, and 16000 to execute commands on infected machines.

The RAT also monitors active Remote Desktop Protocol (RDP) sessions, impersonates users by duplicating security tokens, and enables lateral movement across networks — an especially dangerous feature for enterprise environments.

Persistence mechanisms include modifying Windows service settings and launching watchdog threads to reinstate itself if removed.

To further evade detection, StilachiRAT clears system event logs, disguises API calls, and delays its initial connection to C2 servers by two hours. It also searches for analysis tools such as tcpview.exe and halts execution if they are present, making forensic analysis more difficult.

Mitigation strategies and response

Microsoft advised users to download software only from official sources, as malware like StilachiRAT can masquerade as legitimate applications.

The company also recommended enabling network protection in Microsoft Defender for Endpoint and activating Safe Links and Safe Attachments in Microsoft 365 to guard against phishing-based malware distribution.

Microsoft Defender XDR has been updated to detect StilachiRAT activity. Security professionals are urged to monitor network traffic for unusual connections, inspect system modifications, and track unauthorized service installations that could indicate an infection.

While Microsoft has not observed widespread distribution of StilachiRAT, the company warned that threat actors frequently evolve their malware to bypass security measures. Microsoft said it is continuing to monitor the threat and will provide further updates through its Threat Intelligence Blog.

Mentioned in this article
XRP Turbo
]]>
https://earlybirdsinvest.com/microsoft-uncovers-new-trojan-targeting-crypto-wallet-extensions-on-chrome/feed/ 0 25941