
The source code of the Android- based Cerberus banking Trojan is being auctioned off due to the disbandment of the hacking group behind it .
Recently, an ad was posted on a hacking forum for Russian-speaking hackers, promoting an auction for the malware's source code, in the hope of reaching $100,000.
According to the post, spotted by Hudson Rock, the operator is trying to sell the entire project for a starting price of $50,000. This includes the .APK source code, the module code, the code for the admin panels and the servers. Additionally, if prospective buyers want to integrate the Cerberus banking Trojan into their own toolkits, they are offered Cerberus’s customer base with an active license and the required installation materials.
The seller says the project is being sold due to “lack of time” and due to “the team breaking up.”.
To attract potential buyers, the seller claims that the Android malware generates profits of $10,000 per month.
The Cerberus banking Trojan has been around since 2019 and was detected earlier this month on the Google Play store. The malware managed ’s protections Google. It appeared as a seemingly legitimate currency converter app designed for Spanish-speaking users and was installed on 10,000 devices before it was removed. The app, however, installed the Cerberus banking Trojan on Android via a malicious update.

Researchers from Avast say that in March, the app was operating as a legitimate utility. However, as users increased, the code was transformed into a Cerberus dropper.
Once deployed on a device, the malware attempts to steal credentials from existing financial services and banking applications . The credentials are then sent to the attacker's command-and-control (C2) server . The Trojan is also capable of intercepting mechanisms 2FA, such as OTP passwords.
ThreatFabric researchers said in February that experimental versions of the malware are able to abuse Android accessibility privileges to steal OTPs from Google Authenticator, software designed to enhance 2FA security
The Cerberus banking Trojan has many of the typical capabilities of a Remote Access Trojan (RAT), including theft data, keylogging, phone call recording, and SMS theft. The malware can also lock mobile devices, uninstall applications , and self-destruct.
