LSDroid
Incident posture
Timeline
Summary
Cerberus reported a data breach affecting its anti‑theft application for Android in which usernames and SHA‑1 password hashes stored in a legacy log file were accessed by attackers. The exposed data covered about 96,500 accounts, though only three of those accounts showed any sign of unauthorized access. The company said the passwords had been hashed and uniquely salted multiple times, disabled the legacy logging, deleted the file, and announced plans to migrate to bcrypt for future password storage. No other personal information such as email addresses or device details was taken, and there is no evidence that the stolen data has been made public. The company is working with law enforcement on the incident.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
The only source material supplied in the prompt describes a security incident affecting the Cerberus anti‑theft application for Android. According to the article dated March 28 2014, Cerberus discovered suspicious activity on its servers and blocked it. The investigation revealed that usernames and SHA‑1 password hashes from a legacy log file covering logins between March 1 and March 21 2014 had been accessed. Approximately 96,564 user accounts were impacted by the exposure, although only three accounts showed evidence of actual access by the attackers. No other personal data such as email addresses or device information was reported to have been compromised. Cerberus responded by disabling legacy logging, deleting the file, advising users to change passwords, and planning to migrate to bcrypt for password storage.
The supplied article does not contain any reference to an entity, malware, or incident named “LSDroid”. Consequently, there are no factual details available from the source about the origin, timeline, or scope of an LSDroid‑related event. Without mention of LSDroid in the provided evidence, it is impossible to construct a chronological narrative of any actions taken by attackers targeting that specific subject. Likewise, the source offers no information on impacts attributed to LSDroid, such as numbers of affected users or types of data exposed. Because the incident details for LSDroid are absent from the material, any attempt to describe response actions, containment measures, or consequences would be unsupported speculation. Therefore, based solely on the information given, a detailed narrative of an LSDroid incident cannot be provided.
Sources
Sources available to members: 1 source.