Cerberus

Malware

⚠️ Overview

Cerberus is an Android banking trojan and remote access tool (RAT) first documented in June 2019 by researchers at ThreatFabric. It is operated as a malware-as-a-service (MaaS) by an initial developer known as "Cerberus" and later sold to multiple threat actors, including the group behind the "Coper" variant. The malware targets financial institutions by abusing Android accessibility services to perform overlay attacks and keylogging.

🔧 Technical Capabilities

Cerberus employs a modular architecture with core capabilities including SMS interception, contact exfiltration, keylogging via AccessibilityService, and real-time overlay injection on targeted banking apps. It communicates with its command-and-control (C2) infrastructure using HTTPS and a custom JSON-based protocol, often hosted on compromised servers or bulletproof hosting providers. Persistence is achieved through device admin privileges and repeated system prompts, while evasion techniques include anti-emulator checks, dynamic code loading from encrypted assets, and obfuscation of the dex payload. The malware can also intercept two-factor authentication (2FA) codes by reading SMS messages and forwarding them to the C2. Propagation primarily occurs via fake app downloads from third-party stores or phishing links in SMS messages.

📜 History & Notable Incidents

First spotted in underground forums in May 2019, Cerberus quickly gained popularity among cybercriminals. A major campaign in 2020 targeted users of Spanish banking apps, with the malware masquerading as fake utilities and cryptocurrency wallets. In October 2020, the developer announced a new version (2.0) that added remote access features akin to TeamViewer, enabling live screen recording and command execution. No publicly named high-profile victims or law enforcement actions have been confirmed, but the code was later reused in the "Coper" and "Alien" Android trojans according to reports by Cyble and ThreatFabric.

🔍 Detection Indicators

Known file hashes for Cerberus samples include SHA256 values like 4a3c2b1f... (varies by campaign); behavioral signatures include the registration of a "DeviceAdminReceiver" component named "com.cerberus.admin". Network IOCs involve C2 domains such as cerberus[.]vip and IP addresses associated with Russian hosting providers. Registry keys (on Android device admin settings) are stored under /data/system/device_policies.xml. The malware uses the User-Agent string "Mozilla/5.0 (Linux; Android ; Build/...) AppleWebKit/537.36" for HTTPS communication.

☠️ Risk & Impact

Cerberus causes severe financial damage by exfiltrating online banking credentials, credit card details, and SMS-based 2FA codes, enabling fraudulent transactions. The malware primarily affects individuals and small businesses in Europe, with Spain, Italy, and Germany being the most targeted sectors according to 2020 threat reports. A single campaign can compromise thousands of devices, with average losses per victim exceeding $2,000 based on industry estimates.

🛡️ Mitigation

Defenders should enforce sideloading restrictions via Android Enterprise, enable Google Play Protect, and implement URL filtering for known C2 domains. Recommended detection rules include YARA signatures for Cerberus’s obfuscation patterns (e.g., string "Cerberus" in dex files) and network Snort rules for HTTP POST requests to "/gate.php" endpoints. Organizations should apply patches for Android accessibility service vulnerabilities (CVE-2019-2215 related to kernel exploits sometimes chained by the malware).

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.