
75% of a company's MDM ( Mobile Device Manager ) server was used by hackers to install a Banking Trojan on Android devices .
MDM is a service that allows for remote management of mobile devices and is used by many companies around the world. The company affected by the hackwas using the corresponding command server to more easily perform tasks such as managing device settings across the company, rejecting applications and more.
But in this case, the hackers managed to use MDM to use 75% of the company's devices. The malware they installed on the devicesis a variant of Cerberus and can collect huge amounts of sensitive data of their users. This data is then sent to a c&c server controlled by the hackers.

Cerberus is a banking trojan that was first discovered in June 2019. Through a Malware-as-a-Service (MaaS) model, it allows those using its services to reduce their payload. But worse, an attacker can take full control of a device when carrying out an attack.
Factory reset all devices
Once the malicious actors gained access to the company's MDM server, they exploited the application and after that managed to compromise almost 75% of the company's Android devices.
Security researchers noticed that two applications were installed on a large number of the company's devices, which piqued their curiosity and led them to discover the breach in the MDM server.
Additionally, security researchers at Check Point concluded that to get rid of this malware and the attacker's ability to control infected Android devices, companies should factory reset all Android devices enrolled in the compromised MDM server.
