When the Cerberus code was leaked in late 2020, IBM Trusteer researchers predicted that a new Cerberus mutation was inevitable. Many attackers used the leaked Cerberus code, but without significant changes to the malware . However, the MalwareHunterTeam discovered a new Cerberus variant, known as the Ermac malware, in September 2022.
See also: InTheBox: Over 1,800 malicious phishing forms available

To better understand the new version of Cerberus, we can try to shed light on the operations being carried out behind the scenes by the perpetrator behind Ermac. Although a new version of the malware has been released, we will focus on the original version.
As a descendant of Cerberus, Ermac shares the same source code and fraud capabilities, including stealing bank account credentials and second-factor authentication (2FA) messages delivered to the user via SMS or notification.
It is worth mentioning that the Ermac malware contains a different packer than Cerberus. The Ermac packer is open source and can be found online.

This is further evidence that Ermac could be a new operator and that the attacker is keeping the leak and is constantly evolving the Ermac code base.
A detailed analysis of the user interface (UI) of the Ermac command and control server (C&C) reveals the differences between Cerberus and Ermac and provides a unique insight into Ermac's functionality, customization plan, and features under development. IBM Trusteer researchers discovered two new capabilities in the Ermac malware: ransomware and a virtual private network (VPN) connection.
The data managed by the C&C is organized in a structured table with many columns.
See also: Cerber ransomware: Exploits a serious flaw in Atlassian Confluence
The first column shows the ID generated for each bot. We can also see the various actions and functions of the device: for example, whether the user is viewing this screen, whether various models are loaded, etc.
The next column stores information about the victim's device and operating system version.
The third column stores various tags about the bot's status.
The next column is called GEO and stores information about the country and location of the robot device.
This then includes information about the date and time the malware was installed and the last time the bot successfully connected to the C&C.
The “injection” column contains the various applications in which the malware can perform overlay attacks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The “action” column lists the various actions that the C&C operator can order the bot to perform on the device . These actions include opening the inbox, forwarding calls, clearing app data, and more.
The logs column contains data files that disappeared from the victim's device, including contacts, two-factor authentication, list of installed apps, app notifications, recorded keystrokes, and more.
See also: Gigabud RAT malware infects Android devices
One of the most interesting screens is the “Auto Command,” which is still in beta mode. On the screen, we can see features like sending SMS, opening overlay (screen overlay), downloading contact list, and killbot, which is an Ermac self-destruct switch. We can also see unique commands like “Clear app data” and “Download accounts.”
Source: securityintelligence
