logo

New ‘Perseus’ Android malware checks user notes for secrets

ID: 6db6eab0-f544-5582-bf1b-3d18c1cd8f27

STIX ID: report--6db6eab0-f544-5582-bf1b-3d18c1cd8f27

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-03-19

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Perseus is a new Android banking/infostealer distributed through sideloaded IPTV dropper apps that abuses Accessibility Services to take over devices, capture and stream screenshots, perform HVNC interactions, overlay attacks, keylogging, and uniquely scan popular note-taking apps (e.g., Google Keep, Evernote, OneNote) for passwords and recovery phrases; the campaign targets financial institutions (notably in Turkey and Italy) and cryptocurrency apps and includes strong anti-analysis and evasion checks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.