New Perseus Android Threat Hijacks Devices and Exfiltrates User Notes

A new Android malware named Perseus is actively targeting mobile users by taking over devices and stealing sensitive personal data. Mobile threats constantly evolve to bypass modern security measures, and Perseus perfectly illustrates this trend.

Built on the leaked code of older, well-known malware families like Cerberus and Phoenix, Perseus is not built entirely from scratch.

Instead, it is a heavily upgraded tool designed for maximum control. Security researchers have also found infrastructure connections between Perseus and operations involving Medusa, highlighting a shared network of cybercriminal resources.

Device Takeover and Targeting

After infecting a device, Perseus gains deep control by abusing Android’s Accessibility Services. This powerful system feature is meant to help users with disabilities.

However, Perseus uses it to perform a full remote device takeover. The malware can capture continuous screenshots in real time, compress them, and send them to the attacker.

Alternatively, it can convert the entire user interface into a structured background map. This allows remote operators to programmatically click buttons, scroll, and interact with the device as if it were in their own hands.

Perseus Hijacks Android Devices (Source: threatfabric)
Perseus Hijacks Android Devices (Source: threatfabric)

Extracting Sensitive Notes

The most unusual and damaging feature of Perseus is its ability to spy on personal notes.

While most mobile malware strictly targets banking apps or text messages, Perseus specifically hunts for popular note-taking applications.

Users often save highly sensitive information in their digital notes, such as banking passwords, recovery phrases for cryptocurrency wallets, or confidential personal data.

Perseus Hijacks Android Devices (Source: threatfabric)
Perseus Hijacks Android Devices (Source: threatfabric)

When commanded by the attacker, the malware uses its accessibility permissions to open note applications automatically.

It then systematically clicks through individual notes, copies the private text, and sends it back to the command server without the user ever noticing the background activity.

According to Threat Fabric research, security analysts discovered two distinct development branches of this malware: a stealthy Turkish version and a broader English version.

Perseus Hijacks Android Devices (Source: threatfabric)
Perseus Hijacks Android Devices (Source: threatfabric)

The English branch includes unusual code patterns, such as embedded emojis and detailed debugging logs.

These quirks strongly suggest the malware developers used artificial intelligence or large language models to help write the code.

This represents a concerning shift in cybercrime, where attackers use AI assistants to accelerate malware development and add complex features.

Country / SectorNumber of Targeted Institutions
Turkey17
Italy15
Cryptocurrency9
Poland5
Germany3

Perseus shows that modern threat actors do not need to invent entirely new concepts to be highly dangerous.

By leveraging proven codebases, hiding within popular apps like IPTV services, and adding targeted features such as note extraction, they can create highly effective campaigns.

This evolving threat highlights the severe risks of downloading applications from unverified sources and the growing sophistication of remote mobile attacks.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories