This dangerous Android banking trojan is now available online for anyone to use

Android malware
(Image credit: Shutterstock / quietbits)

The source code for a popular Android banking malware strain has been released online via public forums, raising fears of attacks coming soon.

According to analysts at security firm Kaspersky, the operators of the Cerberus trojan originally attempted to auction off the code to other cybercriminal syndicates, but have now abandoned the material online for anyone to use.

As a result, researchers have witnessed an immediate spike in the number of mobile infections, as cybercriminals harness the complex and sophisticated Android malware to defraud users across Europe.

Android malware

First identified in mid-2019, the Cerberus trojan was originally distributed on underground forums as a malware-as-a-service (MaaS) offering. In other words, any cybercriminal that wished to utilize the banking malware to launch attacks against consumers could pay what essentially amounted to a subscription fee.

According to Kaspersky, the malware has also grown in sophistication since it first hit the scene, with the introduction of mechanisms to bypass two-factor authentication (2FA) and control devices remotely.

Analysis of the source code available online - referred to as Cerberus v2 - shows the trojan is also now able to send and steal SMS codes and launch rigged overlays that sit atop mobile banking applications.

“Cerberus is dead...long live Cerberus. Kaspersky’s findings regarding Cerberus v2 are a warning to everyone impacted by Android security and Android banking security in particular,” said Dmitry Galov, Security Researcher at Kaspersky.

“We’re already seeing an increase in attacks on users since the source code was published. It’s not the first time we’ve seen something like this happen, but this boom of activity since the developers abandoned the project is the biggest developing story we’ve tracked for a while.”

Kaspersky continues to investigate the threat posed by the new edition of Cerberus, but has advised users to take important precautionary measures in the meantime.

To mitigate against the threat posed by Cerberus, the firm claims Android users should download applications from reputable shop fronts (e.g. Google Play Store) only, install system and application updates promptly and use an Android antivirus service for an added layer of protection.

Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras
Security padlock and circuit board to protect data
Trust in digital services around the world sees a massive drop as security worries continue
Samuel and Romy standing very close together in A24's Babygirl movie
Everything new on Max in April 2025, including A24's Babygirl and The Last of Us season 2
An AMD Radeon RX 9070 XT made by Sapphire on a table with its retail packaging
AMD’s secret weapon against Nvidia seems to be stock – way more RX 9070 GPUs are rumored to be hitting shelves than RTX 5000 models
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
Seth Milchick and Kier Eagan's animatronic speaking in Severance season 2 episode 10
Apple TV+ announces Severance has been renewed for season 3 after that devastating finale