The ERMAC 2.0 Android Trojan has managed to increase the number of applications it attacks from 378 to 467, releasing version 2.0. With this move, the ERMAC Android banking Trojan has managed to cover a very wide range of applications for account theft and encryption.

What the Android Trojan wants to do is send stolen login credentials to hackers. The hackers use them to take control of other people's bank and cryptocurrency accounts and commit financial or other forms of fraud.
Fake Bolt Food app
Fake Bolt Food is a fake app targeting the Polish market. It is the first ERMAC malware campaign.

researchers ESET, the hackers released the Android app via the website “bolt-food[.]site”, impersonating a legitimate European food delivery service. At the time of writing, this fake website is still operational.
Users, most likely, end up on this fake website through phishing emails, malicious social media posts, smishing, malicious ads, and more.

The ERMAC 2.0 Android Trojan first sees which applications are installed on the host device and then sends the relevant information to the C2 server. When the victim attempts to launch the real application, a phishing on top of the real GUI.
Cyber security firm analysts report that they have found many similarities in the malware to that of Cerberus, so it appears that the second version of the Android Trojan we mentioned above is based on it.
Although this Android Trojan is reported to be very powerful, it is worth noting that versions Android 11 and Android 12 due to the restrictions it added to prevent misuse of the accessibility service. A good tip to avoid Trojan and Android infections is to avoid downloading APKs and anything other than the PlayStore and especially from sites that you have not confirmed as legitimate.
