logo

Rebirth of a Monster: New ‘Perseus’ Android Malware Hunts for Your Private Notes

ID: dab2275c-4543-572d-bf9a-044b227818d2

STIX ID: report--dab2275c-4543-572d-bf9a-044b227818d2

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-23

Date Updated: 2026-04-23

Author: Ddos

...
...

ThreatFabric researchers uncovered Perseus, a sophisticated Android malware campaign derived from Cerberus and Phoenix that spreads via sideloaded IPTV apps and droppers. Perseus abuses Accessibility Services to enumerate and exfiltrate user notes (including recovery phrases and financial data), supports VNC-like screen capture, overlay credential theft, and remote execution, employs sandbox and realism checks to evade analysis, and is actively observed across Turkey, Italy and other European countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.