Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
credential-stealer-activityloader-delivery-mechanismphishing-campaign-intelligenceendpoint-security-bypass

Perseus Android Malware Steals Secrets from Note-Taking Apps via Fake Streaming APKs

Updated 3mo agoFirst seen Mar 19, 20265 sources

Perseus is a newly reported Android banking trojan distributed through fake IPTV/streaming apps sideloaded from unofficial sources, with observed targeting focused on Turkey and Italy. Researchers said the malware enables broad device compromise, including overlay attacks, credential theft, keylogging, screenshot capture, and near real-time monitoring of user activity. The malware is linked to older Android banking malware lineage, with ThreatFabric reporting that it appears to build on the Phoenix codebase derived from the leaked Cerberus family.

A notable capability is Perseus's deliberate targeting of note-taking applications such as Google Keep, Evernote, and Simple Notes to extract stored content that may include passwords, financial information, and crypto recovery phrases. The campaign uses users' familiarity with sideloading piracy-related streaming apps to reduce suspicion, and one lure cited was Roja Directa TV. Researchers also reported that the dropper can bypass Android 13+ sideloading restrictions and resembles infrastructure previously used to deliver other Android malware families, while an English-language variant showed more refined debugging and logging features, suggesting ongoing development and operational maturity.

Share:
Perseus Android Malware Steals Secrets from Note-Taking Apps via Fake Streaming APKs
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Mar 20, 20263mo ago

ThreatFabric links Perseus to wider targeting and shared criminal infrastructure

ThreatFabric reported that Perseus targets more than 50 institutions across eight countries and nine cryptocurrency platforms, expanding observed activity beyond Turkey and Italy to include Poland, Germany, France, the UAE, and Portugal. The researchers also identified shared infrastructure connections with Medusa and Klopatra, suggesting broader ecosystem ties behind the malware's operations.

Perseus Android Malware Steals User Notes and Enables Full Device Takeover
Mar 19, 20263mo ago

Media reports highlight Perseus as a newly observed note-targeting Android trojan

News coverage summarized ThreatFabric's findings and emphasized that Perseus was being actively distributed through fake streaming apps while targeting users in Turkey and Italy. The reporting also noted ThreatFabric's assessment that this was the first time it had seen Android malware specifically check personal notes for sensitive data.

Oct 1, 20242y ago

ThreatFabric details Perseus anti-analysis and evasion mechanisms

The researchers said Perseus includes anti-analysis protections such as Frida and Xposed detection, root and emulator checks, and a suspicion-scoring system sent to its command-and-control panel. Operators can use this scoring to decide whether to continue activity on a compromised device.

Researchers document Perseus note-stealing and remote takeover features

ThreatFabric disclosed that Perseus abuses Android Accessibility Services for overlay attacks, keylogging, screenshot capture, and near real-time remote interaction with infected devices. The report highlighted a novel capability: scanning note-taking apps such as Google Keep, Samsung Notes, Evernote, OneNote, and similar apps for passwords, recovery phrases, and financial data.

Perseus campaigns spread via fake IPTV and streaming apps

Researchers observed Perseus primarily distributed through IPTV-themed applications and droppers from unofficial sources. The campaigns were described as strongly focused on targets in Turkey and Italy, especially banks and cryptocurrency services.

ThreatFabric identifies Perseus Android malware in active campaigns

ThreatFabric reported a new Android malware family named Perseus being actively distributed in the wild. Researchers said it evolved from the leaked Cerberus codebase and appears to build specifically on Phoenix.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

17 LINKEDOpen in app
Affected products
3 linked
AndroidEvernoteSamsung Notes
Organizations
7 linked
The Hacker NewsSamsung ElectronicsXiaomiThreatFabricMicrosoft CorporationEvernoteGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.