Cyber Security News

Beware of Fake Chrome Update that Installs Cerberus Banking Malware

A new threat looms over Android users, masquerading as a routine Chrome update.

This deceptive tactic breaches trust and directly assaults personal security, installing the notorious Cerberus banking malware onto unsuspecting devices.

Here’s what you need to know about this alarming development and how to protect yourself.

The Lure of the Fake Update

Fake updates are a longstanding tool in the arsenal of cybercriminals, exploiting the general public’s trust in software updates to deliver malicious payloads.

Document

Free Webinar : Mitigating Vulnerability & 0-day Threats

Alert Fatigue that helps no one as security teams need to triage 100s of vulnerabilities. :

  • The problem of vulnerability fatigue today
  • Difference between CVSS-specific vulnerability vs risk-based vulnerability
  • Evaluating vulnerabilities based on the business impact/risk
  • Automation to reduce alert fatigue and enhance security posture significantly

AcuRisQ, that helps you to quantify risk accurately:

While computers have traditionally been the prime targets, the focus has increasingly shifted towards mobile devices, particularly those running the Android operating system.

The latest scheme involves tricking users into downloading what appears to be a Chrome browser update, with file names like “Chrome_Update_[random version number].apk” or simply “Chrome.apk.”

However, these files are far from benign updates; they are carriers for Cerberus, a sophisticated Android banking malware with capabilities that should concern us all.

Broadcom has recently released a report highlighting the prevalence of Cerberus, a banking Trojan masquerading as a fake Chrome update in the mobile threatscape.

The Cerberus Threat

First identified in the cyber threat landscape around 2019, Cerberus is not your average malware.

It boasts remote access capabilities, allowing attackers to control an infected device completely.

This malware specializes in stealing financial information, such as banking login credentials and credit card details, directly from your mobile device.

Its ability to bypass security measures and remain undetected makes it a formidable tool for cybercriminals.

The emergence of malware like Cerberus, disguised as routine updates, underscores the evolving nature of cyber threats.

It’s a stark reminder of the importance of vigilance in the digital age.

By taking proactive steps to verify the authenticity of updates and employing robust security solutions, Android users can significantly mitigate the risk of falling prey to such sophisticated attacks.

With Perimeter81 malware protection, you can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits. All are incredibly harmful and can wreak havoc on your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.

Dhivya

Divya is a Senior Journalist at Cyber Security news covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

7 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago