s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.cerberus

📛 Threat Title

Malware family: Cerberus

Category: Cerberus First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.cerberus`. Printable name: Cerberus.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.cerberus VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.cerberus

IOC database

Type
domain
Value
apk.cerberus
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.cerberus

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.cerberus

References (1)

Remediations (10)

  • web:arxiv.org

    Interpretable models are especially important in ad-versarial domains such as malware analysis, where understanding the rationale behind a classification can guide remediation efforts and enhance model robust-ness. This paper proposes a novel approach for detect-ing and explaining concept drift in malware families over time.

  • web:attack.mitre.org

    Cerberus is a banking trojan whose usage can be rented on underground forums and marketplaces. Prior to being available to rent, the authors of Cerberus claim was used in private operations for two years.

  • web:cybersecuritynews.com

    Microsoft has released urgent security updates to address a zero-day vulnerability in the Windows Cloud Files Mini Filter Driver (cldflt.sys) that is currently being exploited in the wild.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to PCrisk, Cerberus is an Android banking Trojan which can be rented on hacker forums. It was been created in 2019 and is used to steal sensitive, confidential information. Cerberus can also be used to send commands to users' devices and perform dangerous actions.

  • web:news.backbox.org

    The ErrorFather campaign is another example of this pattern. While the TA behind ErrorFather has slightly modified the malware , it remains primarily based on the original Cerberus code, making it inappropriate to classify it as entirely new malware .

  • web:preyproject.com

    Explore the evolution of Cerberus RAT, its leaked source code, modern Android malware threats, and what IT teams must do to stay protected in 2025.

  • web:socradar.io

    Mitigation Measures Mitigating the Cerberus malware campaign requires comprehensive defense measures, including app verification, endpoint security, and user training. The following are recommended mitigation strategies against known techniques used by the campaign.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.infosecurity-magazine.com

    Cerberus Banking Trojan and Variants Cerberus is an Android banking trojan that appeared on underground marketplaces in 2019. It is designed to look like a legitimate app, but is actually a malicious program that can steal login credentials for banking apps, credit card details and other personal information.

  • web:www.sentinelone.com

    Cerber ransomware is infamous for morphing to bypass security. Explore its encryption style, typical targets, and how to keep data off-limits.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.