New Cerberus Android Malware Variant Evades Security Tools: Cyble
ID: 7e18e773-329d-567d-875b-76aa10ccc38b
STIX ID: report--7e18e773-329d-567d-875b-76aa10ccc38b
Feed Name: The Cyber Express
Threat Score
Cyble researchers discovered "ErrorFather," a retooled Cerberus Android banking trojan using a multi-stage dropper, native decryption (libmcfae.so + rbyypivsnw.png), Telegram-based C2, and a DGA to deliver a decrypted.dex payload that performs overlay phishing, keylogging, VNC remote access, and PII theft; approximately 15 samples and active C2 activity were observed and the final payload bypassed VirusTotal detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
