PULSE NAME
DTO malware that takes notes
WHITE Perseus AlienVault 2026-03-19 Modified: 2026-03-19
7
IOCs
LOW VOLUME
Perseus is a new Android threat that builds upon earlier malware families like Cerberus and Phoenix. It enables real-time monitoring and interaction with infected devices through Accessibility-based remote sessions, allowing full Device Takeover. The malware focuses on extracting high-value personal information, including monitoring user notes. It employs strong anti-analysis measures to evade detection. Perseus is primarily distributed through IPTV applications, targeting users in Turkey and Italy. Its capabilities include overlay attacks, keylogging, and systematic exploration of note-taking apps. The malware performs extensive environment checks to detect analysis conditions and assess device risk. Perseus represents the ongoing evolution of mobile malware, adapting to remain effective in an increasingly secure mobile environment.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
Perseus Cerberus Phoenix Ermac Klopatra Medusa
Indicators of Compromise (2 / 7 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 d8081fe3a360d6957829ea2c66b966c2 2026-03-19
FileHash-MD5 e0e427d6dd2f8fa088a1d8a400a64620 2026-03-19