HomeSecurityCerberus banking Trojan: The group disbands and sells the source code

Cerberus banking Trojan: The group disbands and sells the source code

Cerberus banking Trojan

The source code of the Android- based Cerberus banking Trojan is being auctioned off due to the disbandment of the hacking group behind it .

Recently, an ad was posted on a hacking forum for Russian-speaking hackers, promoting an auction for the malware's source code, in the hope of reaching $100,000.

According to the post, spotted by Hudson Rock, the operator is trying to sell the entire project for a starting price of $50,000.  This includes the .APK source code, the module code, the code for the admin panels and the servers. Additionally, if prospective buyers want to integrate the Cerberus banking Trojan into their own toolkits, they are offered Cerberus’s customer base with an active license and the required installation materials.

The seller says the project is being sold due to “lack of time” and due to “the team breaking up.”.

To attract potential buyers, the seller claims that the Android malware generates profits of $10,000 per month.

The Cerberus banking Trojan has been around since 2019 and was detected earlier this month on the Google Play store. The malware managed ’s protections Google. It appeared as a seemingly legitimate currency converter app designed for Spanish-speaking users and was installed on 10,000 devices before it was removed. The app, however, installed the Cerberus banking Trojan on Android via a malicious update.

source code

Researchers from Avast say that in March, the app was operating as a legitimate utility. However, as users increased, the code was transformed into a Cerberus dropper.

Once deployed on a device, the malware attempts to steal credentials from existing financial services and banking applications . The credentials are then sent to the attacker's command-and-control (C2) server . The Trojan is also capable of intercepting mechanisms 2FA, such as OTP passwords.

ThreatFabric researchers said in February that experimental versions of the malware are able to abuse Android accessibility privileges to steal OTPs from Google Authenticator, software designed to enhance 2FA security

The Cerberus banking Trojan has many of the typical capabilities of a Remote Access Trojan (RAT), including theft data, keylogging, phone call recording, and SMS theft. The malware can also lock mobile devices, uninstall applications , and self-destruct.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS