logo

New Perseus Android Banking Malware Monitors Notes Apps to Extract Sensitive Data

ID: 1476a7f5-15ac-5fda-891f-5de24934eda0

STIX ID: report--1476a7f5-15ac-5fda-891f-5de24934eda0

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-03-19

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

ThreatFabric disclosed a new Android banking/DTO malware family named Perseus that evolves Cerberus/Phoenix functionality to steal credentials, monitor notes, and perform real-time accessibility-based remote control. Distributed via dropper apps masquerading as IPTV services and observed targeting Turkey, Italy and other countries, Perseus supports overlay attacks, VNC/HVNC-like remote sessions, numerous C2 commands, environment anti-analysis checks, and lists several app package artifacts used in campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.