logo

Cerberus Malware Fails; Source Code Sold On Darkweb

ID: a29f3a5b-2f82-5fde-9e60-5ba369221876

STIX ID: report--a29f3a5b-2f82-5fde-9e60-5ba369221876

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2025-07-23

Date Updated: 2026-07-20

...
...

The report describes an Android banking trojan (discovered 2019) targeting more than 30 applications—including US, French and Japanese banking apps and numerous non-banking apps—with capabilities such as credential and credit-card theft, overlays, keylogging, SMS harvesting/forwarding, remote app control, C2 resilience, and self-protection; it states the malware infiltrated Google Play Store and its source/operations are being sold on a darkweb market, although Google Play Protect has recently reduced the project's effectiveness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.