Perseus Malware Targets Android Banking, Steals Data from Notes Apps.
Mar 19, 2026 // 15:53 - Lina Schonbein


A newly discovered Android malware family, called Perseus, is being actively spread to take complete control of devices and commit financial crimes, according to cybersecurity researchers.

Perseus is based on Cerberus and Phoenix, but has evolved into a “more adaptable and powerful platform” for compromising Android devices. This is done through dropper apps distributed on phishing websites.

“The malware uses Accessibility to create remote sessions that allow real-time monitoring and precise control of infected devices. This enables full device takeover and targets different regions, especially Turkey and Italy,” ThreatFabric stated in a report shared with The Hacker News.

“Besides stealing credentials, Perseus also monitors user notes, indicating a focus on obtaining valuable personal or financial data.”

Cerberus was initially reported by the Dutch mobile security firm in August 2019. The report highlighted how the malware abused Android’s accessibility service to gain extra permissions and steal sensitive data by displaying fake overlay screens. After its source code was leaked in 2020, several versions appeared, including Alien, ERMAC, and Phoenix.

Some of the apps used to distribute Perseus are listed below:

  • Roja App Directa (com.xcvuc.ocnsxn) – Dropper
  • TvTApp (com.tvtapps.live) – Perseus payload
  • PolBox Tv (com.streamview.players) – Perseus payload

ThreatFabric’s analysis revealed that the malware expands on the Phoenix code, with the developers likely using a large language model (LLM) to help with development. This is suggested by extensive logging within the app and the use of emojis in the code.

Similar to the recently discovered Massiv Android malware, Perseus pretends to be an IPTV service to target users who want to sideload such apps to watch premium content. The campaigns distributing this malware have primarily targeted Turkey, Italy, Poland, Germany, France, the U.A.E., and Portugal.

“By hiding its malicious code within this expected context, Perseus effectively reduces user suspicion and increases the success of infections, blending malicious activity with a common method of distributing such services,” ThreatFabric explained.

Once installed, Perseus functions like other Android banking malware, launching overlay attacks and recording keystrokes to intercept user input in real-time. It displays fake interfaces on top of financial apps and cryptocurrency services to steal login details.

The malware also allows the attacker to remotely issue commands via a control panel and perform fraudulent transactions. Some of the supported commands are:

  • scan_notes, to steal content from note-taking apps like Google Keep, Xiaomi Notes, Samsung Notes, ColorNote Notepad Notes, Evernote, Simple Notes Pro, Simple Notes, and Microsoft OneNote (incorrectly specifies “com.microsoft.onenote” instead of “com.microsoft.office.onenote”). 
  • start_vnc, to begin a near real-time visual stream of the victim’s screen.
  • stop_vnc, to end the remote session.
  • start_hvnc, to transmit a structured representation of the UI hierarchy and permit the threat actor to interact with UI elements programmatically.
  • stop_hvnc, to end the remote session.
  • enable_accessibility_screenshot, to allow screenshots to be taken using the accessibility service.
  • disable_accessibility_screenshot, to prevent screenshots from being taken using the accessibility service.
  • unblock_app, to remove an app from the blocklist.
  • clear_blocked, to clear the entire list of blocked apps.
  • action_blackscreen, to display a black screen overlay to hide activity from the user.
  • nighty, to mute audio.
  • click_coord, to simulate a tap at specific screen coordinates.
  • install_from_unknown, to force installation from unknown sources.
  • start_app, to launch a specified app.

Perseus performs various checks to detect debuggers and analysis tools such as Frida and Xposed. It also verifies if a SIM card is inserted, checks the number of installed apps to see if it’s unusually low, and validates battery values to ensure it’s running on a real device.

The malware combines all this information to calculate an overall “suspicion score,” which is sent to the control panel to determine the next action and whether the operator should proceed with stealing data.

“Perseus demonstrates the ongoing evolution of Android malware, showing how modern threats build on existing families like Cerberus and Phoenix, while introducing targeted enhancements rather than entirely new approaches,” ThreatFabric noted.

“Its capabilities, including Accessibility-based remote control, overlay attacks, and note monitoring, indicate a clear focus on maximizing both interaction with the device and the value of the data collected. This balance between inherited functionality and selective innovation reflects a broader trend toward efficiency and adaptability in malware development.”

#android  #apps.  #banking,  #data  #from  #malware  #news  #notes.  #perseus  #steals  #targets   —   News