New ‘Perseus’ Android malware checks user notes for secrets
ID: 6db6eab0-f544-5582-bf1b-3d18c1cd8f27
STIX ID: report--6db6eab0-f544-5582-bf1b-3d18c1cd8f27
Feed Name: Bleeping Computer
Perseus is a new Android banking/infostealer distributed through sideloaded IPTV dropper apps that abuses Accessibility Services to take over devices, capture and stream screenshots, perform HVNC interactions, overlay attacks, keylogging, and uniquely scan popular note-taking apps (e.g., Google Keep, Evernote, OneNote) for passwords and recovery phrases; the campaign targets financial institutions (notably in Turkey and Italy) and cryptocurrency apps and includes strong anti-analysis and evasion checks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
