Cerberus is an Android banking malware operation and malware-as-a-service offering associated with a criminal crew that marketed, rented, and later attempted to sell the full project on a Russian-speaking underground forum. The operation was promoted as a commercial banking trojan service and reportedly offered source code, operator infrastructure, administration components, and customer relationships as part of the sale. The group stated that the crew had split up, indicating Cerberus functioned as an organized cybercriminal enterprise rather than a single standalone malware sample. Cerberus is designed primarily for financial theft from Android users. Its capabilities include banking-notification spoofing to induce victims to submit credentials, theft of authentication material including two-factor authentication codes, and the ability to launch installed applications on infected devices. Reported anti-analysis features include environmental and movement-based checks intended to distinguish real devices from sandboxed or emulated environments, supporting defense evasion. Cerberus was marketed in underground communities as a reliable Android banking trojan and was rented to other criminals for sustained use, indicating an operator-and-customer model consistent with financially motivated cybercrime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware campaigns associated with the WIN-BS656MOF35Q ISPsystem-derived hostname.
Operators behind the Cerberus Android banking trojan are selling the full malware operation, including source code, infrastructure, admin panel, scripts, and customer list, after previously renting the malware to other criminals as a malware-as-a-service offering.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.