Perseus Android Malware Steals User Notes and Enables Full Device Takeover
ID: bd84518d-64eb-5390-a727-776af58d862e
STIX ID: report--bd84518d-64eb-5390-a727-776af58d862e
Feed Name: cybersecurityNews.com
Perseus is a newly observed Android banking trojan, derived from leaked Cerberus and Phoenix code, distributed via sideloaded fake IPTV apps and a dropper to bypass Android 13+ restrictions; it targets users across multiple countries and over 50 financial institutions and crypto platforms. The malware abuses Android Accessibility Services to perform overlay attacks, keylogging, full remote device takeover, and uniquely scans and exfiltrates contents of note-taking apps (e.g., Google Keep, OneNote, Evernote) to harvest high-value credentials and recovery phrases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
