Cerberus Stalkerware Exploits Google Play for Remote Control of Victims' Devices
Article Content
- •Cerberus Anti-theft is disguised as a legitimate app but functions as stalkerware.
- •The app exploits accessibility services and Firebase for extensive remote control capabilities.
- •Victims can unknowingly have their devices compromised, leading to severe privacy violations.
Cerberus Anti-theft, a stalkerware application, has been available on Google Play since October 4, 2023, masquerading as a legitimate anti-theft tool. The app utilizes accessibility services and Google Firebase to enable abusers to gain extensive remote control over victims' Android devices. Once installed, it can silently capture photos, track locations, record audio, and even wipe devices without the victims' consent. Victims are primarily Android users who unknowingly install the app, believing it to be a security tool. The app's presence on Google Play raises significant concerns about the platform's security vetting processes. As of now, the app remains available, posing a continuous threat to users. The situation highlights the need for improved scrutiny of apps that request extensive permissions. Users are advised to be cautious of apps that require accessibility services for non-essential functions.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Cerberus in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…