A new and particularly worrying threat is making its appearance in the Android ecosystem, with the Perseus malware introducing an unprecedented tactic: searching for sensitive information within users’ personal notes . Unlike traditional mobile trojans that focus on passwords or SMS, Perseus targets data that users themselves manually store, such as recovery phrases, banking details, and personal information.
Distribution via IPTV apps and sideloading
Perseus is mainly distributed through unofficial app stores, disguised as IPTV apps that promise free access to sports broadcasts. It exploits the habit of many users to install APK files outside of Google Play, ignoring security warnings.
This practice has intensified in recent months, as demand for pirated streaming content rises. Similar campaigns have already leveraged the same bait to distribute other banking malware, demonstrating that IPTV is now a primary attack vector.
See also: Interlock Ransomware: Cisco FMC Zero-Day Exploit
Full control of the device via Accessibility Services
Once installed, Perseus exploits Android's Accessibility Services to gain near-complete control over the device. Attackers can continuously take screenshots, simulate user gestures, launch and block applications, and perform overlay attacks to steal credentials.

At the same time, it can activate a black screen to hide malicious actions from the victim, while it has keylogging and remote navigation in the device interface.
Innovation: Targeting note-taking applications
What sets Perseus apart from other threats is its focus on note-taking apps like Google Keep, Samsung Notes, Evernote, and Microsoft OneNote. The malware systematically opens these apps and scans their contents, searching for critical information.
According to researchers, this is the first time that Android malware has so aggressively exploited users' personal notes. Notes often act as a "digital notebook" where passwords, PINs, seed phrases for crypto wallets and other sensitive data are stored.
Perseus: Targeting banks and crypto services
The campaign appears to be primarily focused on users in Turkey and Italy, with dozens of banking institutions on the target list. Perseus is also targeting cryptocurrency applications, significantly increasing the financial risk for victims.
See also: Vidar Stealer 2.0 is distributed via fake game cheats
The use of overlay attacks allows the malware to display fake login forms over legitimate applications, stealing credentials in real time.

Technical roots and use of artificial intelligence
Analysis shows that Perseus is based on code derived from the Phoenix malware, which in turn has roots in the Cerberus trojan. This shows the continuous "evolution" of the same malware ecosystem over the years.
Of particular interest is the English version of the malware, which includes extensive logs and even emojis in the code. Experts believe that these features indicate the use of artificial intelligence tools during development, which accelerates the creation and improvement of malicious tools.
Advanced detection evasion mechanisms
Perseus incorporates multiple checks to avoid analysis. It checks if the device is rooted, if it is running on an emulator, collects SIM, hardware and battery data, and creates a “suspicion score.” If the device is deemed high enough to be detected, the malware can remain inactive.
This approach shows that attackers emphasize the quality of targets rather than just the quantity.
See also: GlassWorm attack: Stolen GitHub tokens used to insert malware into Python repos

How can users be protected?
Avoiding installing apps from unknown sources remains the most basic protection measure. Users should only download apps from Google Play and keep Play Protect for constant device monitoring.
Additionally, storing sensitive data in simple note-taking apps should be avoided. The use of password managersand secure vaults is now a necessary practice.
The appearance of Perseus proves that cybercriminals are turning to more «human» data sources, exploiting users' daily habits. In such an environment, awareness and attention are more critical than ever.
Source: www.bleepingcomputer.com
