

Rewterz Threat Alert – Agent Anubis Malware – Active IOCs
October 11, 2021
Rewterz Threat Alert – Lazarus APT Group – Active IOCs
October 11, 2021
Rewterz Threat Alert – Agent Anubis Malware – Active IOCs
October 11, 2021
Rewterz Threat Alert – Lazarus APT Group – Active IOCs
October 11, 2021Severity
Medium
Analysis Summary
A recent analysis of the Cerberus banking Trojan, performed by Anomali, delves into its current capabilities, including the current malware-as-a-service activity associated with the malware. Cerberus is sold as a malware-as-a-service, likely to fill the gap of black market Android Trojans created when the sale of the Anubis and Red Alert malware ceased. Code analysis led researchers to the conclusion that this family does not share code with other Android banking Trojans and, thus, appears to be newly written. A user named Android is advertising the malware via the XSS.is hacking forum and Twitter. Purchasers of the malware-as-a-service receive access to a control panel for monitoring and control their bots, an APK builder, and an inject generator. Once installed on a victim device, the operators are able to send and intercept SMS messages, open fake login pages, get system information, perform injects, and many other capabilities. One of the most significant capabilities of Cerberus is the SMS functionality as it allows operators to intercept multi-factor authentication codes for accounts using SMS as an additional authentication factor. Overlays used for traditional banking Trojan credential-stealing purposes included those targeting banking, e-commerce, fin-tech,and telecommunication organizations globally.
Impact
- Data Exfiltration
- Information Theft
Indicators of Compromise
SHA-256
- c5a0e64e274883d9030c397a91367549289e7dbdf108cb2064f171b5631ca8ff
- 816a45b4496d97f0f629be79b91790ffa8a5b0007d3ac285da5a744ce608f947
- eca0a2e42bc6f9bbb61045131c25bc9ca831bbc220d366eaef91ab3bfe4ea105
- 11b438f975018edefc4a9ee3339fc3fa5182d59234cabde7f115bcd4ff74f1a1
- 11c81f5b2f0495c6e492788e84ebbcf77658444024a494ace9b983e0c8d6a5d5
- c2081305301afef941a6251ceac4fa0aaf54aed989d6910b17c54d29837277bb
- 0c294507d2c5fb6d35dd2a7c095746b62e5eb1a2292566652f486e1d5d515167
- 7b8ab0b88a6828c03b06fe1600515178b52d37515cd1497ce648b6e0ce612b2b
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.
- Do not download software and files from unofficial and untrusted sources