PULSE NAME
DTO malware that takes notes
WHITE Perseus AlienVault 2026-03-19 Modified: 2026-03-19
7
IOCs
LOW VOLUME
Perseus is a new Android threat that builds upon earlier malware families like Cerberus and Phoenix. It enables real-time monitoring and interaction with infected devices through Accessibility-based remote sessions, allowing full Device Takeover. The malware focuses on extracting high-value personal information, including monitoring user notes. It employs strong anti-analysis measures to evade detection. Perseus is primarily distributed through IPTV applications, targeting users in Turkey and Italy. Its capabilities include overlay attacks, keylogging, and systematic exploration of note-taking apps. The malware performs extensive environment checks to detect analysis conditions and assess device risk. Perseus represents the ongoing evolution of mobile malware, adapting to remain effective in an increasingly secure mobile environment.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
Perseus Cerberus Phoenix Ermac Klopatra Medusa
Indicators of Compromise (2 / 7 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 245c0ce14ccab1e6569275ff36556f19f4da453a 2026-03-19
FileHash-SHA1 b5ba10ae9b17f99915e456d236c0ea5177c0cbe4 2026-03-19