Cerberus is an Android banking trojan operation and malware offering that was advertised and rented on Russian-speaking underground forums and public channels for at least one year. The group behind Cerberus reportedly rented the malware for $12,000 per year, $7,000 for six months, or $4,000 for three months, and later the maintainer reportedly auctioned the entire project with bids starting at $50,000 and a buyout price of $100,000 after stating that the Cerberus crew had split up and could no longer provide continuous support. The sale reportedly included the Cerberus source code, malicious APK and module, admin panel, servers, installation guidance, scripts, and customer contacts. Researchers found Cerberus was not a clone of the leaked Anubis banker. Reported capabilities include anti-sandbox and environmental checks, detection of device movement to help determine whether an infected device is real, spoofing notifications from banking services, prompting victims for banking credentials, theft of two-factor authentication codes, and the ability to run installed apps on infected Android devices. Cerberus was presented in underground marketing as a reliable alternative to Anubis-based banking trojans.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware campaigns associated with the WIN-BS656MOF35Q ISPsystem-derived hostname.
Operators behind the Cerberus Android banking trojan are selling the full malware operation, including source code, infrastructure, admin panel, scripts, and customer list, after previously renting the malware to other criminals as a malware-as-a-service offering.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.