Cerberus Stalkerware Exploits Google Play for Remote Control of Victims' Devices
Article Content
- •Cerberus Anti-theft is disguised as a legitimate app but functions as stalkerware.
- •The app exploits accessibility services and Firebase for extensive remote control capabilities.
- •Victims can unknowingly have their devices compromised, leading to severe privacy violations.
Cerberus Anti-theft, a stalkerware application, has been available on Google Play since October 4, 2023, masquerading as a legitimate anti-theft tool. The app utilizes accessibility services and Google Firebase to enable abusers to gain extensive remote control over victims' Android devices. Once installed, it can silently capture photos, track locations, record audio, and even wipe devices without the victims' consent. Victims are primarily Android users who unknowingly install the app, believing it to be a security tool. The app's presence on Google Play raises significant concerns about the platform's security vetting processes. As of now, the app remains available, posing a continuous threat to users. The situation highlights the need for improved scrutiny of apps that request extensive permissions. Users are advised to be cautious of apps that require accessibility services for non-essential functions.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Cerberus in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…