Cerberus

MITRE ATT&CK: S0480 View on attack.mitre.org

Aliases: Cerberus

First seen
2019-01-01 00:00:00
Malware type
trojan, botnet, credential-stealer
Family
Malware family
Operating systems
android
Related IoCs
53 (47 malicious)
Last IoC activity
2026-08-22 00:17:55
Profile updated
2026-07-07 12:55:42

Targeted industries: financial-services

Context

Cerberus is a banking trojan whose usage can be rented on underground forums and marketplaces. Prior to being available to rent, the authors of Cerberus claim was used in private operations for two years.

Recent IoC activity

47 malicious indicators in Maltiverse are attributed to Cerberus (S0480). The 20 most recently updated:

Detection coverage

  • 1 YARA rules

Malware & tools used

  • Non-Standard Port (attack-pattern)
  • Suppress Application Icon (attack-pattern)
  • Download New Code at Runtime (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • System Checks (attack-pattern)
  • Contact List (attack-pattern)
  • SMS Messages (attack-pattern)
  • GUI Input Capture (attack-pattern)
  • Match Legitimate Name or Location (attack-pattern)
  • Location Tracking (attack-pattern)
  • SMS Control (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Web Protocols (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Software Discovery (attack-pattern)
  • Uninstall Malicious Application (attack-pattern)
  • Keylogging (attack-pattern)
  • Input Injection (attack-pattern)

Detection rules

  • SEKOIA_Trojan_Android_Cerberus (yara-rule)

Reports & references

  • slideshare.net — Cb19 Cyber Threat Landscape In Japan Revealing Threat In The Shadow By Chi En Shen Ashley Oleg Bondarenko (report)
  • threatfabric.com — Alien The Story Of Cerberus Demise (report)
  • resecurity.com — In The Box Mobile Malware Webinjects Marketplace (report)
  • preyproject.com — Cerberus And Alien The Malware That Has Put Android In A Tight Spot (report)
  • threatfabric.com — Ermac Another Cerberus Reborn (report)
  • threatfabric.com — 2020 Year Of The Rat (report)
  • bushidotoken.blogspot.com — Turkey Targeted By Cerberus And Anubis (report)
  • community.riskiq.com — 85B3Db8C (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Cerberus (report)
  • insights.oem.avira.com — In Depth Analysis Of A Cerberus Trojan Variant (report)
  • threatfabric.com — Cerberus A New Banking Trojan From The Underworld (report)
  • go.recordedfuture.com — Cta 2020 1016 (report)
  • blog.cyberint.com — Cerberus Is Dead Long Live Cerberus (report)
  • cyberint.com — Cerberus Is Dead Long Live Cerberus (report)
  • Kaspersky — 106193 (report)
  • forbes.com — Dangerous New Android Trojan Hides From Malware Researchers And Taunts Them On Twitter (report)
  • media.kasperskycontenthub.com — En The State Of Stalkerware 2021 (report)
  • biznet.com.tr — Cerberus (report)
  • labs.bitdefender.com — Apps On Google Play Tainted With Cerberus Banker Malware (report)
  • nur.pub — Cerberus Analysis (report)
  • twitter.com — Androidcerberus (report)
  • github.com — Cerberus Research (report)
  • MITRE ATT&CK — S0480 (report)

External references