New Android Malware Variant ‘ErrorFather’ Successfully Avoids Security Measures

Published:

spot_img

New Cerberus Variant “ErrorFather” Evades Detection

Cyble researchers have uncovered a new and sophisticated variant of the Cerberus Android banking trojan, named “ErrorFather,” that has managed to evade detection by antivirus engines. This new malware variant utilizes a multi-stage dropper to deploy its payload and carries out financial fraud through remote attacks, keylogging, and overlay attacks.

The researchers have noted that the ErrorFather campaign highlights how cybercriminals are repurposing and exploiting leaked malware source code, emphasizing the ongoing threat of Cerberus-based attacks even years after the original malware’s discovery.

Despite being based on older malware strains, the modified Cerberus used in the ErrorFather campaign has successfully evaded detection by antivirus engines, underscoring the risks posed by retooled malware from previous leaks.

The threat actor behind ErrorFather has modified Cerberus variable names, used more obfuscation, and reorganized the code to effectively evade detection. The malware uses a Domain Generation Algorithm to create a Command and Control server, with the overlay technique remaining unchanged from earlier variants.

The researchers have identified about 15 samples used in the ErrorFather campaign, with an active Command and Control server indicating ongoing campaigns. The malware poses as Chrome and Play Store apps, using a session-based dropper to deploy a banking trojan payload.

Overall, the ErrorFather campaign serves as a stark reminder of the evolving tactics used by cybercriminals to carry out financial fraud and the importance of staying vigilant against such threats.

spot_img

Related articles

Recent articles

Snowflake GitHub Actions Vulnerability Allows Command Injection via Crafted Issues

Cybersecurity researchers at Wiz have disclosed a GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository. This vulnerability could be exploited through a...

Data Breach at France’s Tax Authority Affects Approximately 680,000 Individuals

France’s Directorate General of Public Finances (DGFiP) has disclosed a data breach impacting approximately 680,000 individuals. The breach was revealed after a threat actor...

Citrix security advisory AV26-645 warns of active exploitation of CVE-2026-8451 and CVE-2026-8452

Citrix Security Advisory AV26-645: Critical Vulnerabilities in NetScaler Products On June 30, 2026, Citrix issued a security advisory detailing critical vulnerabilities affecting several versions of...

Colombia’s Ministry of Justice Hit by Ransomware Attack Disrupting Services

In a significant cybersecurity incident, Colombia's Ministry of Justice has fallen victim to a ransomware attack that has disrupted critical public services, particularly those...