Cerberus is an Android banking trojan operated as a malware-as-a-service offering and later widely reused after its source code leaked. It is designed primarily to steal banking and other account credentials from Android devices through overlay phishing, accessibility-service abuse, and extensive device surveillance. Cerberus has been associated with campaigns targeting financial institutions and other applications in multiple countries, including Europe, the United States, and Japan, and it has also been used in COVID-19-themed mobile lures.
Cerberus commonly infects victims by masquerading as legitimate Android software, especially fake Adobe Flash Player installers delivered from deceptive websites outside official app stores. After installation it requests accessibility permissions, which it abuses to monitor foreground applications, capture user input, automate malicious actions, and present fake notifications or overlays over attacker-selected apps. It has been observed generating phishing overlays for banking and other applications to harvest credentials and payment data.
Its capabilities extend beyond credential theft. Reported functions include keylogging, collection of SMS messages, sending SMS messages, harvesting contact lists, enumerating installed applications, screenshot capture, audio recording, location tracking, device locking, muting, downloading or removing applications, call-related abuse, theft of authenticator codes, and exfiltration of stolen data to command-and-control infrastructure. Cerberus communicates with its operators over HTTP and has used encrypted command-and-control traffic in some implementations. It also includes anti-analysis and defense-evasion features such as anti-emulator checks, delayed activation based on motion or step-counter data, attempts to disable Google Play Protect, and self-destruct functionality.
Cerberus became especially influential after its 2020 source-code leak, which lowered the barrier for follow-on Android banking malware development. Multiple later families and campaigns have been assessed as derived from or heavily influenced by Cerberus, including ERMAC and other modified forks. The leak helped sustain Cerberus-derived activity well beyond the decline of the original operation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Tools known as ‘cryptors’ are often used by malware authors... obfuscating or modifying their code to evade detection signatures.
Agent Smith can impersonate any popular application on an infected device, and the core malware disguises itself as a legitimate Google application.
provided a self-destruct mechanism to remove traces of the bot to prevent post-incident analysis.
Hercules automatically finds decryption key for actual DEX of the given Cerberus sample, decrypts it, then decrypts configuration parameters in the actual payload.
It uses the device's accelerometer to measure steps. 'The Trojan uses this counter to activate the bot,' ThreatFabric explains... This counter-measure 'prevents the Trojan from running and being analyzed in dynamic analysis environments (sandboxes) and on test devices.'
startInject Triggers the overlay attack against the specified application | push Shows a push notification (clicking on the notification will result in launching specified app)
Given these permissions, many capabilities can be identified... Keylogging from within applications;
It uses the device's accelerometer to measure steps. 'The Trojan uses this counter to activate the bot,' ThreatFabric explains... This counter-measure 'prevents the Trojan from running and being analyzed in dynamic analysis environments (sandboxes) and on test devices.'
startInject Triggers the overlay attack against the specified application | push Shows a push notification (clicking on the notification will result in launching specified app)
Given these permissions, many capabilities can be identified... Keylogging from within applications;
Most of the popular applications provide common stalkerware functionality such as: ... Taking screenshots
It uses almost identical data structures when communicating with the C2... Compared to the original Cerberus, ERMAC uses different encryption scheme in communication with the C2: the data is encrypted with AES-128-CBC
48 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
59 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan spread via fake COVID information apps requesting excessive permissions to exfiltrate personal data.
A named crypto drainer active in 2024, associated with phishing-based theft of cryptocurrency via malicious smart contract approvals.
Older Android banking trojan whose leaked source code was used as the basis for Perseus.
Referenced as a previous Android threat family that Perseus builds upon.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.