March 2, 2020 By David Bisson 2 min read

The Cerberus Android malware family has gained the ability to steal its victims’ two-factor authentication (2FA) tokens and screen lock credentials.

According to ThreatFabric, the operators of Cerberus released a new variant of their creation in mid-January 2020. This version came with a new remote-access Trojan (RAT) capability that allowed Cerberus to traverse the file system and download its contents. It also enabled the malware to launch TeamViewer and establish connections to it.

Such functionality granted full access over an infected device to Cerberus’ handlers. As such, they could leverage that functionality to change the device’s settings, install or remove any app, use an app, and conduct espionage on the device’s activity.

Not only that, but the threat actors could use a simple overlay in Cerberus requiring its victims to unlock their device. The overlay analyzed by researchers stole victims’ screen lock codes/credentials, allowing the threat actors to remotely unlock a device for the purpose of performing fraud.

Attackers could also abuse the Accessibility features to steal 2FA codes from the Google Authentication app for the purpose of bypassing authentication services.

A Look Back at Cerberus

ThreatFabric first came across Cerberus in June 2019. What stuck out for researchers at that time was the fact that Cerberus lacked features that could have helped the malware to avoid detection in the process of abusing stolen information and perpetuating fraud. Not only that, but the malware operators also used a Twitter account at the time to both publish promotional materials for their creation and make fun of the antivirus community.

A few months later in September 2019, security firm Buguroo revealed that it had detected a new version of Cerberus targeting Spanish and Latin American entities.

Defending Against Cerberus Android Malware

Security professionals can help their organizations defend against Cerberus Android malware and similar threats by investing in a unified endpoint management (UEM) platform for the purpose of monitoring mobile devices and tracking how they report to the network environment. Companies should also leverage artificial intelligence (AI)-powered tools to track threats like Cerberus that use evasion tactics and other techniques to fly under the radar.

More from

What we can learn from the best collegiate cyber defenders

3 min read - This year marked the 19th season of the National Collegiate Cyber Defense Competition (NCCDC). For those unfamiliar, CCDC is a competition that puts student teams in charge of managing IT for a fictitious company as the network is undergoing a fundamental transformation. This year the challenge involved a common scenario: a merger. Ten finalist teams were tasked with managing IT infrastructure during this migrational period and, as an added bonus, the networks were simultaneously attacked by a group of red…

A spotlight on Akira ransomware from X-Force Incident Response and Threat Intelligence

7 min read - This article was made possible thanks to contributions from Aaron Gdanski.IBM X-Force Incident Response and Threat Intelligence teams have investigated several Akira ransomware attacks since this threat actor group emerged in March 2023. This blog will share X-Force’s unique perspective on Akira gained while observing the threat actors behind this ransomware, including commands used to deploy the ransomware, active exploitation of CVE-2023-20269 and analysis of the ransomware binary.The Akira ransomware group has gained notoriety in the current cybersecurity landscape, underscored…

New proposed federal data privacy law suggests big changes

3 min read - After years of work and unsuccessful attempts at legislation, a draft of a federal data privacy law was recently released. The United States House Committee on Energy and Commerce released the American Privacy Rights Act on April 7, 2024. Several issues stood in the way of passing legislation in the past, such as whether states could issue tougher rules and if individuals could sue companies for privacy violations. With the American Privacy Rights Act of 2024, the U.S. government established…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today