PULSE NAME
DTO malware that takes notes
WHITE Perseus AlienVault 2026-03-19 Modified: 2026-03-19
7
IOCs
LOW VOLUME
Perseus is a new Android threat that builds upon earlier malware families like Cerberus and Phoenix. It enables real-time monitoring and interaction with infected devices through Accessibility-based remote sessions, allowing full Device Takeover. The malware focuses on extracting high-value personal information, including monitoring user notes. It employs strong anti-analysis measures to evade detection. Perseus is primarily distributed through IPTV applications, targeting users in Turkey and Italy. Its capabilities include overlay attacks, keylogging, and systematic exploration of note-taking apps. The malware performs extensive environment checks to detect analysis conditions and assess device risk. Perseus represents the ongoing evolution of mobile malware, adapting to remain effective in an increasingly secure mobile environment.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
Perseus Cerberus Phoenix Ermac Klopatra Medusa
Indicators of Compromise (3 / 7 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 1ea8360c4d3b7ccea50e9f19630be9d23df26ac713799e2f8457520c0d29bdda 2026-03-19
FileHash-SHA256 2524e9d5ed1e55332fe2d1cc0e7ad4e2656ad5ca624199e6f619325979b3529a 2026-03-19
FileHash-SHA256 56d3bb5e8771b41b11d368e70ddd26fe6f1e7bd00b3aafcfd4c34ef62f87093d 2026-03-19