Friday, September 11, 2026

Source Code of ERMAC V3.0 Malware Exposed by ‘changemeplease’ Password

A significant security breach has exposed the complete source code of ERMAC V3.0, a sophisticated banking trojan that targets over 700 financial applications worldwide.

The leak, discovered by cybersecurity firm Hunt.io in March 2024, was made possible by a surprisingly weak default password: “changemeplease.”

The discovery occurred when Hunt.io researchers identified an open directory containing the complete ERMAC V3.0 source code archive.

This rare exposure of an active Malware-as-a-Service platform provides unprecedented insight into one of the most advanced mobile banking trojans currently operating in the wild.

ERMAC has undergone significant evolution since its inception. Early versions were built using leaked Cerberus source code, while version 2.0 incorporated substantial portions of the Hook botnet’s codebase by late 2023.

Open directory containing ERMAC's source code, discovered by Hunt.io
Open directory containing ERMAC’s source code, discovered by Hunt.io

The newly uncovered version 3.0 represents a major advancement, expanding the malware’s capabilities to target more than 700 banking, shopping, and cryptocurrency applications through sophisticated form injection techniques.

The leaked source code revealed a comprehensive malware ecosystem consisting of five main components: a PHP and Laravel-based backend, a React-based frontend panel, a Golang exfiltration server, Docker configuration files, and an Android builder panel for creating customized malware variants.

Critical Security Vulnerabilities

Analysis of the source code uncovered multiple critical security flaws that could be exploited to disrupt ERMAC operations.

 ERMAC Panel UI
 ERMAC Panel UI

These include a hardcoded JWT secret token, static admin bearer token, and most notably, default root credentials using the password “changemeplease.” Additionally, the system allows open account registration directly through its API, potentially granting unauthorized access to the admin panel.

Using advanced search capabilities, Hunt.io researchers identified multiple active ERMAC infrastructure components still operating online.

Form inject management system with adversaries able to upload and modify targeted applications.
Form inject management system with adversaries able to upload and modify targeted applications.

The investigation revealed four unique command-and-control servers and four exfiltration servers using the distinctive authentication header “LOGIN | ERMAC.”

The malware demonstrates sophisticated operational security measures, including AES-CBC encrypted communications and geographic restrictions that prevent execution in Commonwealth of Independent States countries.

Before installation, ERMAC verifies it’s not running in an emulator environment and requests extensive device permissions for SMS access, background operation, and process termination capabilities.

This source code leak provides cybersecurity professionals with valuable intelligence for developing countermeasures against ERMAC campaigns. The exposed infrastructure details and operational vulnerabilities offer concrete opportunities to disrupt ongoing malicious activities and protect potential victims.

The ERMAC V3.0 leak underscores the continued evolution of mobile banking trojans and highlights how weak security practices, even among cybercriminals, can expose sophisticated malicious operations to security researchers and law enforcement agencies.

AWS Security Services: 10-Point Executive Checklist - Download for Free

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth

Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture...

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

Nearly one in 10 internet-exposed LiteLLM AI gateways accepted...

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

Skullcandy Dime 3 wireless earbuds have a serious vulnerability...

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

Threat actors are increasingly exploiting Active Directory replication mechanisms...

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

Threat actors are exploiting anticipation around Grand Theft Auto...

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O...

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

Palo Alto Networks has announced a high-severity buffer overflow...

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out...

Related Articles

Recent News