Perseus Android Malware Steals Notes, Enables Full Device Takeover
Key Takeaways Perseus is a new Android banking trojan built upon the leaked source code of Cerberus and Phoenix, featuring advanced credential theft, real-time monitoring, and a unique ability to...
Key Takeaways
- Perseus is a new Android banking trojan built upon the leaked source code of Cerberus and Phoenix, featuring advanced credential theft, real-time monitoring, and a unique ability to steal personal notes.
- The malware targets users in Turkey, Italy, Poland, Germany, France, UAE, and Portugal, spreading via fake IPTV applications distributed outside the Google Play Store.
- Perseus leverages Android Accessibility Service permissions for full device takeover, enabling silent screen monitoring, input interception, overlay attacks, keylogging, and unauthorized transactions.
- A standout feature is its ability to silently read content from popular note-taking applications like Google Keep, Evernote, and Samsung Notes, making it a significant threat to sensitive personal and financial data.
Perseus: A New Evolution in Android Banking Malware
A sophisticated new Android banking trojan, dubbed Perseus, has emerged, showcasing an alarming advancement in mobile malware capabilities. This threat represents a significant leap forward in the ongoing evolution of malicious software targeting Android devices, as detailed in recent analysis.
Table Of Content
Perseus is a derivative of previously leaked malware, specifically leveraging the source code of Cerberus and directly incorporating elements from the Phoenix codebase. It integrates credential theft, real-time device monitoring, and a distinctive, rarely seen ability to discreetly extract personal notes from infected devices. This combination positions Perseus as one of the most potent Android threats currently active.
Distribution and Infection Vectors
The malware is actively disseminated through campaigns primarily focused on users in Turkey and Italy, with its reach extending to Poland, Germany, France, the UAE, and Portugal, as well as various cryptocurrency platforms.
Threat actors distribute Perseus by disguising it as fake IPTV applications. This tactic bypasses the Google Play Store by exploiting users’ familiarity with sideloading APK files. By masquerading as a legitimate streaming service, Perseus effectively reduces user suspicion, thereby increasing infection rates. Furthermore, a dropper application is employed to circumvent installation restrictions present in Android 13 and later versions, making the infection process significantly more difficult to detect.
ThreatFabric analysts identified Perseus as part of an ongoing campaign, noting its connections to infrastructure shared with other prominent malware families, including Medusa and Klopatra. The malware’s name itself was derived directly from the command-and-control (C2) login panel observed during campaign analyses, confirming its deliberate and purpose-built nature. Analysts have also identified two primary branches of the malware: an English-language version equipped with extensive debugging features, and a more covert Turkish-language variant. Both versions are actively targeting financial institutions and user data across multiple geographical regions.
Operational Capabilities
Upon successful installation, Perseus aggressively requests Accessibility Service permissions. These permissions form the core of its operational framework, allowing the malware to monitor the device screen, intercept user input, and simulate touch interactions, all without any visible indication of activity to the user.
The malware executes overlay attacks by displaying deceptive login pages over legitimate banking applications, while its integrated keylogging functionality records every keystroke made by the user. When these capabilities are combined with its robust remote control features, an attacker gains complete interactive control over the compromised device. This enables them to perform fraudulent activities and authorize transactions without the victim’s knowledge or consent.
The broader impact of Perseus is substantial. By targeting over 50 institutions across eight countries and nine cryptocurrency platforms, it poses a severe financial threat. Its capacity for full device takeover, coupled with its ability to remain hidden, underscores the significant advancements in modern Android banking malware.
Taking Notes: A Capability Others Lack
What truly differentiates Perseus from the majority of Android banking Trojans is its unique ability to specifically target note-taking applications on a victim’s device. Many individuals inadvertently store sensitive information such as passwords, cryptocurrency recovery phrases, and financial account details within these apps, often unaware of the inherent risks.
Perseus exploits this common practice through a command identified as scan_notes. This command identifies installed note applications and silently opens each one, systematically reading through its stored content. This entire process occurs without any user interaction.
Perseus executes this process by leveraging Android Accessibility Services to autonomously navigate the interface of each application. It moves through individual notes, triggers tap actions to open entries, captures the visible text, and then performs a back-navigation action before proceeding to the next entry. This entire routine operates silently in the background, providing no visible indication to the victim. All captured note data is subsequently logged and transmitted to the attacker’s command-and-control server, alongside other stolen credentials and device information.
The note-taking applications specifically monitored by Perseus include Google Keep, Xiaomi Notes, Samsung Notes, ColorNote, Evernote, Microsoft OneNote, Simple Notes Pro, and Simple Notes. This extensive targeting highlights a calculated effort to extract high-value personal and financial data that victims typically presume is secure on their devices.
What You Should Do
- Avoid Sideloading Applications: Refrain from installing applications from unofficial app stores or unknown sources. Stick to the Google Play Store for all app downloads.
- Keep Google Play Protect Enabled: Ensure that Google Play Protect is always active on your Android device to benefit from its built-in malware scanning.
- Update Your Device: Regularly update your Android operating system and all applications to the latest versions to receive critical security patches.
- Never Store Sensitive Information in Notes: Crucially, avoid storing passwords, cryptocurrency wallet recovery phrases, banking details, or any other sensitive credentials within note-taking applications. Malware leveraging Accessibility Services can access this data without alerting you.
- Review App Permissions: Be vigilant about the permissions requested by applications, especially Accessibility Service permissions, and only grant them to trusted apps that genuinely require them.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.