Perseus is an Android banking trojan designed for device takeover and financial fraud. It is derived in part from leaked Cerberus source code and incorporates elements of the Phoenix codebase. Active campaigns have primarily targeted Android users in Turkey and Italy, with additional targeting reported in Poland, Germany, France, Portugal, the United Arab Emirates, and cryptocurrency-service users.
Perseus is delivered in counterfeit IPTV and television-streaming applications distributed outside official Android marketplaces, including via phishing sites that induce victims to sideload dropper applications. The malware requests Accessibility Service permissions, which it uses to monitor screen content, intercept user input, simulate touch interactions, and remotely operate the infected device. It can deploy overlays over legitimate financial and cryptocurrency applications to harvest credentials, record keystrokes, and facilitate unauthorized transactions.
A distinctive Perseus capability is the silent discovery and reading of installed note-taking applications. It uses Accessibility Services to navigate those applications and collect stored text, targeting high-value data such as passwords, financial details, and cryptocurrency recovery phrases. Collected note content can be sent to operator-controlled infrastructure. Perseus has also been observed in English-language and more discreet Turkish-language variants, both focused on financial-account compromise and user-data theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
It can lay fake bank login screens over real apps, record what the owner types, intercept the one-time codes from text messages and login apps that are meant to keep accounts safe, and control the screen from afar.
Malware has gained more sophisticated capabilities, including full Device Takeover (DTO), credential theft (using overlays and keylogging)
Notably, Perseus also monitors user notes from various applications, aiming to extract high-value personal or financial information.
It can lay fake bank login screens over real apps, record what the owner types, intercept the one-time codes from text messages and login apps that are meant to keep accounts safe, and control the screen from afar.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison for similar Android Accessibility-permission abuse and fake streaming-app lures.
Mentioned only as a comparison for Android Accessibility-permission abuse and fake streaming-app lures; no further operational details are provided.
Android banking trojan delivered via unofficial streaming apps; uses Android accessibility abuse to overlay fake bank logins, capture keystrokes, intercept one-time codes, remotely control the device, and read note-taking apps for saved passwords and crypto recovery phrases.
Android malware used for device takeover and financial fraud. It is distributed via dropper apps on phishing sites posing as IPTV services, abuses Android accessibility services, performs overlay attacks, captures keystrokes, steals credentials from financial and cryptocurrency apps, and monitors user notes to extract valuable personal or financial information.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.