PULSE NAME
DTO malware that takes notes
WHITE Perseus AlienVault 2026-03-19 Modified: 2026-03-19
7
IOCs
LOW VOLUME
Perseus is a new Android threat that builds upon earlier malware families like Cerberus and Phoenix. It enables real-time monitoring and interaction with infected devices through Accessibility-based remote sessions, allowing full Device Takeover. The malware focuses on extracting high-value personal information, including monitoring user notes. It employs strong anti-analysis measures to evade detection. Perseus is primarily distributed through IPTV applications, targeting users in Turkey and Italy. Its capabilities include overlay attacks, keylogging, and systematic exploration of note-taking apps. The malware performs extensive environment checks to detect analysis conditions and assess device risk. Perseus represents the ongoing evolution of mobile malware, adapting to remain effective in an increasingly secure mobile environment.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
Perseus Cerberus Phoenix Ermac Klopatra Medusa
Indicators of Compromise (7)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 d8081fe3a360d6957829ea2c66b966c2 2026-03-19
FileHash-MD5 e0e427d6dd2f8fa088a1d8a400a64620 2026-03-19
FileHash-SHA1 245c0ce14ccab1e6569275ff36556f19f4da453a 2026-03-19
FileHash-SHA1 b5ba10ae9b17f99915e456d236c0ea5177c0cbe4 2026-03-19
FileHash-SHA256 1ea8360c4d3b7ccea50e9f19630be9d23df26ac713799e2f8457520c0d29bdda 2026-03-19
FileHash-SHA256 2524e9d5ed1e55332fe2d1cc0e7ad4e2656ad5ca624199e6f619325979b3529a 2026-03-19
FileHash-SHA256 56d3bb5e8771b41b11d368e70ddd26fe6f1e7bd00b3aafcfd4c34ef62f87093d 2026-03-19