Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Cursor 0-day Vulnerability Allows Arbitrary Code Execution
August 19, 2026
Critical Microsoft Copilot CoSnitch Flaw Lets Attackers Steal Sensitive Data
August 19, 2026
Cl0p Hackers Exploit Critical PTC Windchill CVE-2023-XXXX to Steal Data
August 19, 2026
Home/Threats/Perseus Android Malware Steals Notes, Enables Full Device Takeover
Threats

Perseus Android Malware Steals Notes, Enables Full Device Takeover

Key Takeaways Perseus is a new Android banking trojan built upon the leaked source code of Cerberus and Phoenix, featuring advanced credential theft, real-time monitoring, and a unique ability to...

Jennifer sherman
Jennifer sherman
March 20, 2026 4 Min Read
73 0

Key Takeaways

  • Perseus is a new Android banking trojan built upon the leaked source code of Cerberus and Phoenix, featuring advanced credential theft, real-time monitoring, and a unique ability to steal personal notes.
  • The malware targets users in Turkey, Italy, Poland, Germany, France, UAE, and Portugal, spreading via fake IPTV applications distributed outside the Google Play Store.
  • Perseus leverages Android Accessibility Service permissions for full device takeover, enabling silent screen monitoring, input interception, overlay attacks, keylogging, and unauthorized transactions.
  • A standout feature is its ability to silently read content from popular note-taking applications like Google Keep, Evernote, and Samsung Notes, making it a significant threat to sensitive personal and financial data.

Perseus: A New Evolution in Android Banking Malware

A sophisticated new Android banking trojan, dubbed Perseus, has emerged, showcasing an alarming advancement in mobile malware capabilities. This threat represents a significant leap forward in the ongoing evolution of malicious software targeting Android devices, as detailed in recent analysis.

Table Of Content

  • Key Takeaways
  • Perseus: A New Evolution in Android Banking Malware
  • Distribution and Infection Vectors
  • Operational Capabilities
  • Taking Notes: A Capability Others Lack
  • What You Should Do

Perseus is a derivative of previously leaked malware, specifically leveraging the source code of Cerberus and directly incorporating elements from the Phoenix codebase. It integrates credential theft, real-time device monitoring, and a distinctive, rarely seen ability to discreetly extract personal notes from infected devices. This combination positions Perseus as one of the most potent Android threats currently active.

Distribution and Infection Vectors

The malware is actively disseminated through campaigns primarily focused on users in Turkey and Italy, with its reach extending to Poland, Germany, France, the UAE, and Portugal, as well as various cryptocurrency platforms.

Threat actors distribute Perseus by disguising it as fake IPTV applications. This tactic bypasses the Google Play Store by exploiting users’ familiarity with sideloading APK files. By masquerading as a legitimate streaming service, Perseus effectively reduces user suspicion, thereby increasing infection rates. Furthermore, a dropper application is employed to circumvent installation restrictions present in Android 13 and later versions, making the infection process significantly more difficult to detect.

ThreatFabric analysts identified Perseus as part of an ongoing campaign, noting its connections to infrastructure shared with other prominent malware families, including Medusa and Klopatra. The malware’s name itself was derived directly from the command-and-control (C2) login panel observed during campaign analyses, confirming its deliberate and purpose-built nature. Analysts have also identified two primary branches of the malware: an English-language version equipped with extensive debugging features, and a more covert Turkish-language variant. Both versions are actively targeting financial institutions and user data across multiple geographical regions.

Operational Capabilities

Upon successful installation, Perseus aggressively requests Accessibility Service permissions. These permissions form the core of its operational framework, allowing the malware to monitor the device screen, intercept user input, and simulate touch interactions, all without any visible indication of activity to the user.

The malware executes overlay attacks by displaying deceptive login pages over legitimate banking applications, while its integrated keylogging functionality records every keystroke made by the user. When these capabilities are combined with its robust remote control features, an attacker gains complete interactive control over the compromised device. This enables them to perform fraudulent activities and authorize transactions without the victim’s knowledge or consent.

The broader impact of Perseus is substantial. By targeting over 50 institutions across eight countries and nine cryptocurrency platforms, it poses a severe financial threat. Its capacity for full device takeover, coupled with its ability to remain hidden, underscores the significant advancements in modern Android banking malware.

Taking Notes: A Capability Others Lack

What truly differentiates Perseus from the majority of Android banking Trojans is its unique ability to specifically target note-taking applications on a victim’s device. Many individuals inadvertently store sensitive information such as passwords, cryptocurrency recovery phrases, and financial account details within these apps, often unaware of the inherent risks.

Perseus exploits this common practice through a command identified as scan_notes. This command identifies installed note applications and silently opens each one, systematically reading through its stored content. This entire process occurs without any user interaction.

Perseus executes this process by leveraging Android Accessibility Services to autonomously navigate the interface of each application. It moves through individual notes, triggers tap actions to open entries, captures the visible text, and then performs a back-navigation action before proceeding to the next entry. This entire routine operates silently in the background, providing no visible indication to the victim. All captured note data is subsequently logged and transmitted to the attacker’s command-and-control server, alongside other stolen credentials and device information.

The note-taking applications specifically monitored by Perseus include Google Keep, Xiaomi Notes, Samsung Notes, ColorNote, Evernote, Microsoft OneNote, Simple Notes Pro, and Simple Notes. This extensive targeting highlights a calculated effort to extract high-value personal and financial data that victims typically presume is secure on their devices.

What You Should Do

  • Avoid Sideloading Applications: Refrain from installing applications from unofficial app stores or unknown sources. Stick to the Google Play Store for all app downloads.
  • Keep Google Play Protect Enabled: Ensure that Google Play Protect is always active on your Android device to benefit from its built-in malware scanning.
  • Update Your Device: Regularly update your Android operating system and all applications to the latest versions to receive critical security patches.
  • Never Store Sensitive Information in Notes: Crucially, avoid storing passwords, cryptocurrency wallet recovery phrases, banking details, or any other sensitive credentials within note-taking applications. Malware leveraging Accessibility Services can access this data without alerting you.
  • Review App Permissions: Be vigilant about the permissions requested by applications, especially Accessibility Service permissions, and only grant them to trusted apps that genuinely require them.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwarePatchSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

FBI and Thai Police Disrupt Southeast Asia Cyber Scam Centers Targeting Americans

Next Post

VoidStealer Bypasses Chrome ABE, Steals Data Without Injection

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
WordPress Sites Hijacked for StopAndProtect Malware C2 Servers
August 18, 2026
Critical MLflow SSRF vulnerability CVE-2023-XXXX exploited in the wild
August 18, 2026
French Tax Authority Data Breach Exposes Over 600,000 Users’ Personal Tax Data
August 18, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us