Perseus is a newly reported Android banking trojan distributed through fake IPTV/streaming apps sideloaded from unofficial sources, with observed targeting focused on Turkey and Italy. Researchers said the malware enables broad device compromise, including overlay attacks, credential theft, keylogging, screenshot capture, and near real-time monitoring of user activity. The malware is linked to older Android banking malware lineage, with ThreatFabric reporting that it appears to build on the Phoenix codebase derived from the leaked Cerberus family.
A notable capability is Perseus's deliberate targeting of note-taking applications such as Google Keep, Evernote, and Simple Notes to extract stored content that may include passwords, financial information, and crypto recovery phrases. The campaign uses users' familiarity with sideloading piracy-related streaming apps to reduce suspicion, and one lure cited was Roja Directa TV. Researchers also reported that the dropper can bypass Android 13+ sideloading restrictions and resembles infrastructure previously used to deliver other Android malware families, while an English-language variant showed more refined debugging and logging features, suggesting ongoing development and operational maturity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
ThreatFabric reported that Perseus targets more than 50 institutions across eight countries and nine cryptocurrency platforms, expanding observed activity beyond Turkey and Italy to include Poland, Germany, France, the UAE, and Portugal. The researchers also identified shared infrastructure connections with Medusa and Klopatra, suggesting broader ecosystem ties behind the malware's operations.
News coverage summarized ThreatFabric's findings and emphasized that Perseus was being actively distributed through fake streaming apps while targeting users in Turkey and Italy. The reporting also noted ThreatFabric's assessment that this was the first time it had seen Android malware specifically check personal notes for sensitive data.
The researchers said Perseus includes anti-analysis protections such as Frida and Xposed detection, root and emulator checks, and a suspicion-scoring system sent to its command-and-control panel. Operators can use this scoring to decide whether to continue activity on a compromised device.
ThreatFabric disclosed that Perseus abuses Android Accessibility Services for overlay attacks, keylogging, screenshot capture, and near real-time remote interaction with infected devices. The report highlighted a novel capability: scanning note-taking apps such as Google Keep, Samsung Notes, Evernote, OneNote, and similar apps for passwords, recovery phrases, and financial data.
Researchers observed Perseus primarily distributed through IPTV-themed applications and droppers from unofficial sources. The campaigns were described as strongly focused on targets in Turkey and Italy, especially banks and cryptocurrency services.
ThreatFabric reported a new Android malware family named Perseus being actively distributed in the wild. Researchers said it evolved from the leaked Cerberus codebase and appears to build specifically on Phoenix.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourcethreatfabric.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.