A new Android malware named Perseus is actively targeting mobile users by taking over devices and stealing sensitive personal data. Mobile threats constantly evolve to bypass modern security measures, and Perseus perfectly illustrates this trend.
Built on the leaked code of older, well-known malware families like Cerberus and Phoenix, Perseus is not built entirely from scratch.
Instead, it is a heavily upgraded tool designed for maximum control. Security researchers have also found infrastructure connections between Perseus and operations involving Medusa, highlighting a shared network of cybercriminal resources.
Device Takeover and Targeting
After infecting a device, Perseus gains deep control by abusing Android’s Accessibility Services. This powerful system feature is meant to help users with disabilities.
However, Perseus uses it to perform a full remote device takeover. The malware can capture continuous screenshots in real time, compress them, and send them to the attacker.
Alternatively, it can convert the entire user interface into a structured background map. This allows remote operators to programmatically click buttons, scroll, and interact with the device as if it were in their own hands.

Extracting Sensitive Notes
The most unusual and damaging feature of Perseus is its ability to spy on personal notes.
While most mobile malware strictly targets banking apps or text messages, Perseus specifically hunts for popular note-taking applications.
Users often save highly sensitive information in their digital notes, such as banking passwords, recovery phrases for cryptocurrency wallets, or confidential personal data.

When commanded by the attacker, the malware uses its accessibility permissions to open note applications automatically.
It then systematically clicks through individual notes, copies the private text, and sends it back to the command server without the user ever noticing the background activity.
According to Threat Fabric research, security analysts discovered two distinct development branches of this malware: a stealthy Turkish version and a broader English version.

The English branch includes unusual code patterns, such as embedded emojis and detailed debugging logs.
These quirks strongly suggest the malware developers used artificial intelligence or large language models to help write the code.
This represents a concerning shift in cybercrime, where attackers use AI assistants to accelerate malware development and add complex features.
| Country / Sector | Number of Targeted Institutions |
|---|---|
| Turkey | 17 |
| Italy | 15 |
| Cryptocurrency | 9 |
| Poland | 5 |
| Germany | 3 |
Perseus shows that modern threat actors do not need to invent entirely new concepts to be highly dangerous.
By leveraging proven codebases, hiding within popular apps like IPTV services, and adding targeted features such as note extraction, they can create highly effective campaigns.
This evolving threat highlights the severe risks of downloading applications from unverified sources and the growing sophistication of remote mobile attacks.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.