Cerberus
Malware⚠️ Overview
Cerberus is an Android banking trojan and remote access tool (RAT) first documented in June 2019 by researchers at ThreatFabric. It is operated as a malware-as-a-service (MaaS) by an initial developer known as "Cerberus" and later sold to multiple threat actors, including the group behind the "Coper" variant. The malware targets financial institutions by abusing Android accessibility services to perform overlay attacks and keylogging.
🔧 Technical Capabilities
Cerberus employs a modular architecture with core capabilities including SMS interception, contact exfiltration, keylogging via AccessibilityService, and real-time overlay injection on targeted banking apps. It communicates with its command-and-control (C2) infrastructure using HTTPS and a custom JSON-based protocol, often hosted on compromised servers or bulletproof hosting providers. Persistence is achieved through device admin privileges and repeated system prompts, while evasion techniques include anti-emulator checks, dynamic code loading from encrypted assets, and obfuscation of the dex payload. The malware can also intercept two-factor authentication (2FA) codes by reading SMS messages and forwarding them to the C2. Propagation primarily occurs via fake app downloads from third-party stores or phishing links in SMS messages.
📜 History & Notable Incidents
First spotted in underground forums in May 2019, Cerberus quickly gained popularity among cybercriminals. A major campaign in 2020 targeted users of Spanish banking apps, with the malware masquerading as fake utilities and cryptocurrency wallets. In October 2020, the developer announced a new version (2.0) that added remote access features akin to TeamViewer, enabling live screen recording and command execution. No publicly named high-profile victims or law enforcement actions have been confirmed, but the code was later reused in the "Coper" and "Alien" Android trojans according to reports by Cyble and ThreatFabric.
🔍 Detection Indicators
Known file hashes for Cerberus samples include SHA256 values like 4a3c2b1f... (varies by campaign); behavioral signatures include the registration of a "DeviceAdminReceiver" component named "com.cerberus.admin". Network IOCs involve C2 domains such as cerberus[.]vip and IP addresses associated with Russian hosting providers. Registry keys (on Android device admin settings) are stored under /data/system/device_policies.xml. The malware uses the User-Agent string "Mozilla/5.0 (Linux; Android
☠️ Risk & Impact
Cerberus causes severe financial damage by exfiltrating online banking credentials, credit card details, and SMS-based 2FA codes, enabling fraudulent transactions. The malware primarily affects individuals and small businesses in Europe, with Spain, Italy, and Germany being the most targeted sectors according to 2020 threat reports. A single campaign can compromise thousands of devices, with average losses per victim exceeding $2,000 based on industry estimates.
🛡️ Mitigation
Defenders should enforce sideloading restrictions via Android Enterprise, enable Google Play Protect, and implement URL filtering for known C2 domains. Recommended detection rules include YARA signatures for Cerberus’s obfuscation patterns (e.g., string "Cerberus" in dex files) and network Snort rules for HTTP POST requests to "/gate.php" endpoints. Organizations should apply patches for Android accessibility service vulnerabilities (CVE-2019-2215 related to kernel exploits sometimes chained by the malware).
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.