/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers find an Android malware strain Cerberus that can extract and steal one-time passwords generated by Google's Authenticator mobile app

Catalin Cimpanu / ZDNet :

ZDNet Catalin Cimpanu

Context & Ripple Effects

Cerberus started life as a banking trojan that overlays fake login screens on financial apps; researchers now report it can also pull one-time passwords straight out of Google's Authenticator app, turning the second factor itself into loot. The technique rides on a weakness that has been public since 2014 — researchers detailed in March how Android apps can capture Authenticator's one-time codes via screenshots.

The finding lands in a stretch where every major 2FA channel has been shown attackable on Android: Check Point later tied SMS-code theft to Rampant Kitten's spyware, and Kaspersky's 2025 report showed store-listed apps using OCR to lift crypto wallet recovery phrases from device images. What was pitched as the fix for password theft is increasingly the target.

First-order effects

  • Users whose handsets carry Cerberus lose the protection their Authenticator codes were supposed to provide — an attacker with the trojan can read the OTP at generation time, defeating the 'something you have' factor without ever touching the user's password.
  • Google's Authenticator shifts from neutral infrastructure to a named attack surface, putting pressure on Google to harden the app against screen-capture and extraction by other apps.

Second-order effects

  • Google faces renewed scrutiny of Play Store vetting, the same pressure point behind its removal of 25 apps caught stealing Facebook credentials via phishing overlays — malware families keep reaching distribution despite the review process.
  • Security teams evaluating 2FA now have documented theft paths for both major software channels — SMS codes (Rampant Kitten) and authenticator-app TOTP (Cerberus) — weakening the case for either as a default and pushing buyers toward options that don't live on the handset.

Third-order effects

  • If code-stealing keeps maturing from proof-of-concept to commodity trojan features, software-delivered one-time passwords get priced out of high-risk accounts, accelerating a structural move toward phishing-resistant authentication such as hardware-bound credentials.
  • The pattern across Cerberus, Rampant Kitten, and the OCR wallet-phrase apps points to malware economics shifting from stealing credentials to stealing the factors meant to replace them — making the endpoint OS's app-isolation guarantees, not any single app, the real control point.

The trend: Mobile malware is climbing the authentication stack — from passwords to SMS codes to authenticator-app tokens — eroding each software-based second factor in turn.

Discussion

  • @martijn_grooten Martijn Grooten on x
    Finding out that mobile malware abuses Accessibility functions always hurts a little bit more. In this overview of mobile RATs, Cerebrus uses it to steal 2FA tokens from Google Authenticator running on the same device https://www.threatfabric.com/ ...
  • @evacide Eva on x
    Me: This is a neat trick. Also me: endless screaming. https://twitter.com/...
  • @adam_k_levin Adam Levin on x
    A new version of the “Cerberus” Android banking trojan will be able to steal one-time codes generated by the Google Authenticator app and bypass 2FA-protected accounts. https://www.zdnet.com/...
  • @sonicwall @sonicwall on x
    A new version of the #cerberus banking malware can steal 2-factor authentication codes from the google authenticator app. via @ZDNet http://r.socialstudio.radian6.com/ ... #2FA #cybersecurity
  • @appenz Guido Appenzeller on x
    The Cerberus Banking Trojan can now steal Google Authenticator Codes from Android phones. This was inevitable. Smart phones are rich & complex devices and as a result have a wide attack surface. Instead, keep TOTP seeds on a #YubiKey. Or use FIDO. https://www.threatfabric.com/ ..…
  • @j_opdenakker John Opdenakker on x
    Before y'all start losing your mind: - malware running on your device means you're screwed anyway - otp stealing feature not yet live - soft tokens via authenticator app are still a good middleground between #security and #UX for the avg user https://www.zdnet.com/... #Infosec