Rebirth of a Monster: New ‘Perseus’ Android Malware Hunts for Your Private Notes
ID: dab2275c-4543-572d-bf9a-044b227818d2
STIX ID: report--dab2275c-4543-572d-bf9a-044b227818d2
Feed Name: securityonline.info
ThreatFabric researchers uncovered Perseus, a sophisticated Android malware campaign derived from Cerberus and Phoenix that spreads via sideloaded IPTV apps and droppers. Perseus abuses Accessibility Services to enumerate and exfiltrate user notes (including recovery phrases and financial data), supports VNC-like screen capture, overlay credential theft, and remote execution, employs sandbox and realism checks to evade analysis, and is actively observed across Turkey, Italy and other European countries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
