logo

New Cerberus Android Malware Variant Evades Security Tools: Cyble

ID: 7e18e773-329d-567d-875b-76aa10ccc38b

STIX ID: report--7e18e773-329d-567d-875b-76aa10ccc38b

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2024-10-14

Date Updated: 2026-04-23

Author: Paul Shread

...
...

Cyble researchers discovered "ErrorFather," a retooled Cerberus Android banking trojan using a multi-stage dropper, native decryption (libmcfae.so + rbyypivsnw.png), Telegram-based C2, and a DGA to deliver a decrypted.dex payload that performs overlay phishing, keylogging, VNC remote access, and PII theft; approximately 15 samples and active C2 activity were observed and the final payload bypassed VirusTotal detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.