IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Android Cerberus malware can hack Google Authenticator

Cerberus now has remote access trojan capabilities

An Android malware strain is now capable of stealing one-time passcodes (OTP) from the popular Google Authenticator app, security researchers have warned.

According to a report published this week by ThreatFabric, the Cerberus Trojan virus has been restructured and enhanced with the ability to steal multi-factor authentication (2FA) tokens from the Google Authenticator application.

Google Authenticator was launched in 2010 in order to make 2FA more secure. The application replaces the need to use SMS messaging to deliver OTPs, as that way they can be intercepted when travelling through insecure mobile networks. Instead, the codes are generated on the user’s smartphone and are valid for 30 seconds only.

The Cerberus malware was discovered last year as an Android banking Trojan. However, it was recently enhanced with RAT (Remote Access Trojan) abilities, significantly increasing its threat level.

As well as being able to tamper with the authenticator application, the Cerberus can also steal device screen-lock credentials - PIN codes and swipe patterns alike, allowing the hackers to “remotely unlock the device in order to perform fraud when the victim is not using the device”.

Related Resource

6 ways your business could suffer if you don’t backup Office 365

Office 365 makes it easy to lose valuable data regularly, unpredictably, unintentionally, and for good

Download now

According to ThreatFabric, Cerberus can target communication applications such as Gmail, Outlook, and Telegram, as well as numerous banking applications, including Lloyds Bank Mobile Banking, Wells Fargo Mobile, and Santander.

“We believe that this variant of Cerberus is still in the test phase but might be released soon,” ThreatFabric warned in their blog post.

“Having an exhaustive target list including institutions from all over the world, combined with its new RAT capability, Cerberus is a critical risk for financials offering online banking services.”

Earlier this month, Google purged as many as 24 Android applications from the Google Play Store, after they were found to harbour malware and rogueware. The apps, which totalled in 382 million active installations, were all linked to Chinese tech firm Shenzhen HAWK.

Featured Resources

The state of Salesforce: Future of business

Three articles that look forward into the changing state of Salesforce and the future of business

Free Download

The mighty struggle to migrate SAP to the cloud may be over

A simplified and unified approach to delivering Enterprise Transformation in the cloud

Free Download

The business value of the transformative mainframe

Modernising on the mainframe

Free Download

The Total Economic Impact™ Of IBM FlashSystem

Cost savings and business benefits enabled by FlashSystem

Free Download

Most Popular

Why convenience is the biggest threat to your security
Sponsored

Why convenience is the biggest threat to your security

8 Aug 2022
How to boot Windows 11 in Safe Mode
Microsoft Windows

How to boot Windows 11 in Safe Mode

29 Jul 2022
Microsoft successfully tests emission-free hydrogen fuel cell system for data centres
data centres

Microsoft successfully tests emission-free hydrogen fuel cell system for data centres

29 Jul 2022