Security researchers have discovered that Android malware can steal one-time passwords (OTPs) generated through Google Authenticator. Google Authenticator is a mobile app that offers two-factor authentication (2FA) for different online accounts.
Google released the Authenticator app in 2010. The app generates six-digit or eight-digit unique codes, which users enter into login forms to access online accounts.
Google Authenticator was launched as an alternative to passwords SMS-based Google Authenticator generates the passwords on the smartphone , so the passwords are not transmitted over unsecured mobile networks. Therefore, accounts - that use Authenticator passwords as 2FA are considered more secure based passwords.

However, the research team at Dutch security firm ThreatFabric discovered that the Android malware, Cerberus, has gained the ability to steal OTP codes generated by Authenticator. Cerberus is a relatively new Android banking trojan that first appeared in June 2019.
"By abusing accessibility permissions, Android malware can now steal 2FA codes from Google Authenticator," the ThreatFabric team said.
“When the [Authenticator] application is executed, the Trojan can take the interface content and send it to a command-and-control server,” they added.
According to the researchers, the new version of Cerberus, which includes this feature, is not yet being sold on hacking forums.
"We believe this variant of Cerberus is still in the testing phase, but may be released soon," the researchers said.

Bypassing 2FA to access bank accounts
ThreadFabric researchers pointed out that current versions of the Android malware Cerberus are already very sophisticated. They include many of the features of remote access trojans (RATs), which are a higher class of malware.
These RAT features allow Cerberus operators to remotely connect to an infected device, use the victim's banking credentials to gain access to bank accounts, and then use the Authenticator's OTP codes to bypass 2FA, if applicable.
ThreatFabric researchers believe that Cerberus will primarily be used to bypass 2FA for bank accounts. However, hackers will also be able to use it to compromise many other accounts (e.g. email, coding repositories, social media accounts, intranets, and more).
So far, not many malware have managed to bypass 2FA protection.
If the new feature introduced in Cerberus works properly, then Android malware will join the elite of malicious software.
Cerberus' new capabilities are detailed in a report from ThreatFabric, which summarizes recent upgrades and other Android malware.
