Cerberus Android Trojan
First observed in June 2019, Cerberus is a modular Android trojan-as-a-service sold on a number of hacking forums.
Summary
First observed in June 2019, Cerberus is a modular Android trojan-as-a-service sold on a number of hacking forums.
Affected platforms
The following platforms are known to be affected:
Threat details
As with most Android malware, Cerberus is delivered disguised as legitimate applications via the Google Play application store or third-party. When downloaded, it will disable Google Play Protect security services before hiding itself on the device.
Once installed, Cerberus will attempt to extract user credentials and financial information from other applications on the device. It will also attempt to phish user information when a number of banking-related websites are visited. Certain variants of Cerberus are able to log keystrokes, and forward calls and messages.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect a trojan infection, ensure that:
|
Last edited: 14 February 2020 2:54 pm