
A new Android threat called Perseus is scanning user notes to steal private data like passwords, recovery keys, or money information.
Spread through unofficial app stores disguised as IPTV services, Perseus gives attackers full control of the device, allows them to take screenshots, and perform overlay attacks.
By pretending to be IPTV apps, which are often used for streaming pirated content, the attacker uses the user’s familiarity with installing APKs from sources other than the Google Play store and disregarding security warnings.
This trend has become noticeable in recent months, as users look for ways to watch live sports for free or at a low cost. Lately, attackers have used the IPTV app trick to spread the Massiv Android banking malware.
According to researchers at the mobile security firm ThreatFabric, Perseus is mainly focused on financial institutions in Turkey and Italy, and also targets cryptocurrency services.
One of the apps carrying the malware is called Roja Directa TV, a popular sports streaming platform known for copyright issues and being shut down.
The Perseus installer can bypass security measures on Android 13 and newer and it’s the same one used to deliver the Klopatra and Medusa malware.
According to ThreatFabric researchers, “Perseus seems to build upon the Phoenix code,” which came from the Cerberus source code that leaked nearly six years ago.
In a report released today, the researchers state that the malware has two versions, one in Turkish and a more refined one in English that includes better debugging and extra convenience features.
The English version has detailed logging and emojis in the code, which strongly suggests that AI was used in its development.
The focus on Turkey is also shown by the list of financial institutions in that country that are targeted (17), followed by Italy with 15, Poland with 5, Germany (3), and France (2). The malware also targets 9 cryptocurrency apps.
By abusing Android Accessibility Services, Perseus gives attackers complete remote control over infected devices, allowing them to:
Perseus also targets Android note-taking applications, including Google Keep, Xiaomi Notes, Samsung Notes, ColorNote, Evernote, Microsoft OneNote, and Simple Notes.
ThreatFabric researchers say this is the first time they have observed an Android threat looking for private details in personal notes on the device.
“While many Android malware families mainly try to steal login details or intercept communications, this feature indicates a wider interest in personal and relevant data,” the ThreatFabric report states.
“Notes often contain sensitive information like passwords, recovery phrases, financial details, or personal thoughts, which make them a valuable target for attackers.”
The English version of the malware uses Accessibility Services to systematically open the note-taking apps one by one and scan the notes saved in them.
Before running on a device, Perseus does thorough anti-analysis and evasion checks, including looking at root status, emulator fingerprints, SIM details, hardware profile, battery data, Bluetooth presence, number of apps, and Google Play Services availability. It then creates a “suspicion score” that it sends to the command-and-control (C2) server.
Based on the score, the attacker decides whether to continue with stealing data.
To reduce the risk, Android users should avoid installing APKs from untrustworthy sources and only download official streaming apps from the Google Play Store. Also, ensure that Play Protect is enabled and use it to regularly scan the device for potential threats.
#android #data #for #malware #news #notes. #perseus #scans #secret-stealing #sensitive #targets #trojan #user — News
© Bulletproof Servers. All rights reserved.