Google Authenticator App Codes Can Be Stolen by Android Malware Cerberus: ThreatFabric

Google has not issued a statements over the reports however, the tech giant might be working on an update.

Advertisement
By Abhik Sengupta | Updated: 27 February 2020 18:58 IST
Highlights
  • The particular malware is likely to be not live yet
  • It possesses the capability of accessing bank details
  • Google is yet to issue a response

Google authenticator app is at the potential risk of breach, report claims

Security analysts claim that a relatively new Android malware can now extract one-time passwords (OTP) generated by Google's authenticator app. The Google Authenticator app was launched in 2010 as an alternative to SMS-based one-time passcodes, and is used for two-factor authentication (2FA) for various Google apps and services such as Gmail and YouTube. Google has not released any statements in response to the claims made by the analysts in the report.

According to ThreatFabric, the team has found an Google Authenticator OTP-stealing capability in recent samples of Cerberus, the Android banking malware that first emerged in June 2019. However, it was also pointed out that the malware is likely to be not live as no advertisements were made in underground forums.

Advertisement

"We believe that this variant of Cerberus is still in the test phase but might be released soon. Having an exhaustive target list including institutions from all over the world, Cerberus is a critical risk for financials offering online banking services," analysts said.

Despite this, the note also pointed out that Cerberus should not be taken lightly, as it includes the capabilities of remote access trojans (RATs), an advance class of malware. This malware can even pose serious threats to online banking services.

Advertisement

To use Google Authenticator, a user is required to download the app from the respective app store of the device. Instead of receiving a text message from the operator as typically seen in 2FA, the app displays six to eight-digits-long unique codes that users must enter while trying logging into an account. Find all the relevant information about the Authenticator app here.

As pointed out in the beginning, Google has not issued statements over the concerns. However, the Alphabet-owned tech giant might likely be working on updates regarding its authenticator app as no cases of breach of this nature were earlier reported. We've reached out to Google for a statement, and will update this space if we hear back.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases This Week: 24, Band Melam, Nukkad Naatak, Prathichaya, and More
  2. Vivo X500 Series Screen Sizes Leaked, Could Arrive With 144Hz Displays
  3. Xbox Chief Asha Sharma Sets New Strategy, Says Will Reevaluate Exclusives
  4. WhatsApp Could Soon Offer Messenger-Like Chat Bubbles on Android
  5. Vivo Y6 5G Debuts With 7,200mAh Battery, 6.75-Inch Screen at This Price
  6. Detailed Oppo Find X9 Ultra Teardown Video Shows Us What's Inside
  7. Redmi Note 17 Pro Max Leak Reveals Chipset, Camera Details
  8. Honor MagicPad 3 Pro 12.3 Debuts With 10,100mAh Battery, Slim 4.8mm Profile
  9. OnePlus Pad 4 First Impressions
  1. Uranus’ Outer Rings May Reveal Hidden Moons, Scientists Say
  2. WhatsApp Is Finally Working on Adding Support for Android's Notification Bubbles Feature
  3. Realme C100x Tipped to Launch in India Soon as Key Specifications and Design Surface Online
  4. Morgan Stanley Announces MSILF Stablecoin Reserves Portfolio for Issuers
  5. Jio Youth and Gaming Plan With Snapchat+, FanCode and Gemini Pro Launched: Price, Benefits
  6. Infinix GT 50 Pro Launched With Dimensity 8400 Ultimate, HydroFlow Liquid Cooling, Shoulder Triggers: Price, Features
  7. Adobe Previews New Agentic AI Workflows for Marketing Tasks at Adobe Summit 2026
  8. Microsoft Gaming Rebrands to Xbox, Debuts New Logo as Xbox Chief Says Company Reevaluating Exclusive Games
  9. Instagram Launches Instants App With Disappearing Photos to Rival Snapchat, BeReal
  10. Prathichaya (2026) Now Streaming Online: What You Need to Know
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.