Skip to main content
Mallory
Malware

Perseus

Perseus is an Android banking trojan actively distributed in the wild and designed for device takeover and financial fraud. Reporting states it is built on leaked Cerberus source code and draws from the Phoenix codebase. ThreatFabric named the malware from the command-and-control login panel and identified at least two branches, including an English-language version with extensive debugging features and a more discreet Turkish-language version.

Perseus is distributed primarily through fake IPTV and television streaming applications, including unofficial streaming apps delivered via phishing sites and sideloaded APKs outside Google Play. Campaigns observed in Spain and Italy also linked Perseus to malicious RojaDirecta-themed streaming apps, and attackers have used droppers, including one described as bypassing Android 13+ installation restrictions. The infection chain relies on social engineering and user sideloading rather than exploitation of software vulnerabilities.

Once installed, Perseus abuses Android Accessibility Services to monitor the screen in real time, intercept user input, simulate touch interactions, and support remote control and full device takeover. Documented capabilities include overlay attacks against banking and cryptocurrency applications, fake login screens for credential harvesting, keylogging, interception of one-time codes, and fraud-enabling remote interaction with the device.

A notable capability is silent harvesting of data from note-taking applications. Perseus includes a command described as scan_notes to identify installed note apps and autonomously read their contents via Accessibility Services. Reported targeted apps include Google Keep, Samsung Notes, Xiaomi Notes, ColorNote, Evernote, Microsoft OneNote, Simple Notes Pro, and Simple Notes. Researchers state the malware seeks passwords, financial details, and cryptocurrency recovery phrases stored in notes, then logs and forwards the extracted content to command-and-control infrastructure.

ThreatFabric reported that Perseus campaigns primarily target users in Turkey and Italy, with additional activity affecting Poland, Germany, France, the United Arab Emirates, and Portugal. The malware was reported to target more than 50 institutions across eight countries and nine cryptocurrency platforms. Shared infrastructure was also observed with Medusa and Klopatra. High-confidence behaviors and targeting described in the source material center on Android users, especially those lured into sideloading unofficial streaming/IPTV apps.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

13 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1566PhishingEvidence1

Perseus is distributed through dropper apps found on phishing sites, masquerading as IPTV services to trick users into sideloading them.

Execution

2 techniques
T1204User ExecutionEvidence1
TacticExecution

Threat actors distribute it through fake IPTV applications, a tactic that sidesteps the Google Play Store by exploiting users’ familiarity with sideloading APK files.

T1204.002Malicious FileEvidence3
TacticExecution

Users typically encounter them on websites or ads and are asked to download and install them manually... By doing so, users: Bypass protections designed to screen apps for malicious behaviour.

Persistence

1 technique
T1546.008Accessibility FeaturesEvidence4

One of the clearest warning signs is a request for Accessibility Services after opening the app. This level of access is not required for streaming and is frequently abused by banking malware to monitor input or interact with other apps.

T1546.008Accessibility FeaturesEvidence4

One of the clearest warning signs is a request for Accessibility Services after opening the app. This level of access is not required for streaming and is frequently abused by banking malware to monitor input or interact with other apps.

Stealth

1 technique
T1036MasqueradingEvidence2
TacticStealth

our MTI research team observed a clear increase in unofficial IPTV apps containing malware, notably apps masquerading as RojaDirecta apps for Android.

Credential Access

4 techniques
T1056Input CaptureEvidence3

It can lay fake bank login screens over real apps, record what the owner types, intercept the one-time codes from text messages and login apps that are meant to keep accounts safe, and control the screen from afar.

T1056.001KeyloggingEvidence3

Malware has gained more sophisticated capabilities, including full Device Takeover (DTO), credential theft (using overlays and keylogging)

T1555Credentials from Password StoresEvidence1

Perseus... even reads note-taking apps for saved passwords and crypto recovery phrases.

T1649Steal or Forge Authentication CertificatesEvidence1

It can... intercept the one-time codes from text messages and login apps that are meant to keep accounts safe.

Collection

4 techniques
T1005Data from Local SystemEvidence2

Notably, Perseus also monitors user notes from various applications, aiming to extract high-value personal or financial information.

T1056Input CaptureEvidence3

It can lay fake bank login screens over real apps, record what the owner types, intercept the one-time codes from text messages and login apps that are meant to keep accounts safe, and control the screen from afar.

T1056.001KeyloggingEvidence3

Malware has gained more sophisticated capabilities, including full Device Takeover (DTO), credential theft (using overlays and keylogging)

T1113Screen CaptureEvidence1

It moves through individual notes, triggers tap actions to open entries, captures the text, then performs a back-navigation action before moving to the next.

T1219Remote Access ToolsEvidence2

It can... control the screen from afar.

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence1

All captured note data is logged and forwarded to the attacker’s command-and-control server alongside other stolen credentials and device information.

INDICATORS OF COMPROMISE

IOCs tracked for this family

4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
3 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app2 years ago
hash.sha256●●●●●●●●●●●●View more in app2 years ago
hash.sha256●●●●●●●●●●●●View more in app2 years ago
hash.sha256●●●●●●●●●●●●View more in app2 years ago
ACTIVITY FEED

Recent activity

6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

the hacker newsNews
Jun 5, 2026
FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins

Android banking trojan delivered via unofficial streaming apps; uses Android accessibility abuse to overlay fake bank logins, capture keystrokes, intercept one-time codes, remotely control the device, and read note-taking apps for saved passwords and crypto recovery phrases.

Read more
scworldNews
Mar 20, 2026
Perseus Android malware evolves from Cerberus and Phoenix for device takeover | brief | SC Media

Android malware used for device takeover and financial fraud. It is distributed via dropper apps on phishing sites posing as IPTV services, abuses Android accessibility services, performs overlay attacks, captures keystrokes, steals credentials from financial and cryptocurrency apps, and monitors user notes to extract valuable personal or financial information.

Read more
cyber security newsNews
Mar 20, 2026
Perseus Android Malware Steals User Notes and Enables Full Device Takeover

Android banking trojan that steals credentials, performs overlay attacks and keylogging, enables remote control and full device takeover, monitors devices in real time, and can silently read data from note-taking applications to capture sensitive information such as passwords and cryptocurrency recovery phrases.

Read more
the hacker newsNews
Mar 20, 2026
Google Adds 24-Hour Wait for Unverified App Sideloading to Reduce Malware and Scams

Android malware targeting users in Turkey and Italy to conduct device takeover and financial fraud.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching4

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping13

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.