logo

ErrorFather's Cerberus: Amplifying Cyber Threats

ID: 415f2be0-94db-55c7-9f63-d63d1a839c6b

STIX ID: report--415f2be0-94db-55c7-9f63-d63d1a839c6b

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-03-03

Date Updated: 2026-07-20

...
...

**Executive summary:** Cyble Research identified the ErrorFather campaign delivering a Cerberus-derived Android banking trojan via multi-stage session droppers, native decryption libraries, and encrypted payloads; the final payload implements keylogging, overlay phishing, VNC screen capture, and a DGA-backed resilient C2, with active Telegram-based coordination and multiple samples observed in Sept–Oct 2024.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.