On March 19, 2026, security research firm ThreatFabric described Perseus, Android malware designed to take over devices and facilitate financial fraud. The analysed samples were distributed as streaming or IPTV apps through unofficial websites and stores.
One capability drew particular attention: an English-language variant can search for selected note-taking apps, open them, and browse their contents. For a business, a work phone can therefore become an exposure point for credentials or business information copied onto it.
What ThreatFabric observed
Perseus builds on earlier Android malware families and includes remote-control capabilities. ThreatFabric describes its use of Accessibility services to interact with the phone’s interface, observe the screen, and perform actions. These capabilities can let operators access banking apps or other services open on the device.
The note-scanning behaviour is specific to the English-language variant studied. A command called scan_notes checks for several predefined apps, including Google Keep, Samsung Notes, Xiaomi Notes, Evernote, ColorNote, and Simple Notes. ThreatFabric says the package identifier associated with OneNote in the sample is incorrect. Researchers also identified a Turkish variant with different functionality.
Why notes matter to business teams
Notes may contain passwords, recovery codes, financial information, or other details saved for convenience. If malware can read the screen and control apps, simply keeping secrets organised in notes does not protect copies stored there.
ThreatFabric’s findings describe specific samples; they do not show that every note-taking app or every Android phone is exposed. The report lists targeted institutions in several countries, including two in France, but by itself does not establish that a French organisation was compromised.
The IPTV lure and APK installation
Observed campaigns presented the malware as a streaming app, including apps for sports content. The installation flow encouraged people to download an APK from an unofficial channel and grant permissions that let the software act on the interface.
This fits a series of Android campaigns documented by ThreatFabric: other banking malware, such as Massiv, was also distributed as IPTV apps, while StreamRat used ads to promote fake streaming apps. These are separate malware families. Their common thread is the streaming lure and risky installation, not an identical ability to read notes.
Practical steps for small businesses
Include work phones in the inventory of devices that access email, business apps, or authentication factors. To reduce exposure:
- install apps from trusted sources and decline APKs prompted by ads, messages, or unfamiliar websites;
- keep Android and apps up to date, and leave built-in protections enabled;
- review requests for Accessibility access carefully. These services are legitimate, but an app enabling them without an obvious need should be checked;
- avoid copying business secrets into ordinary notes or shared files;
- document whom to contact and how to revoke sessions if a phone looks suspicious.
Security options vary by Android version, device maker, and configuration. An Accessibility permission is not, by itself, proof of infection: the app and its reason for requesting access matter.
If a phone looks suspicious
Alert the IT owner and follow the company’s incident procedure. Do not only delete the app if the phone granted sensitive access or was used to sign in to work accounts. From a clean device, revoke active sessions and replace potentially exposed secrets, starting with email and accounts that can reset other access.
Preserve the phone so it can be examined under the organisation’s process. An immediate factory reset may erase useful evidence. If the team lacks incident-response expertise, contact a specialist provider.
How Soclyde fits
Soclyde does not detect Perseus or protect an Android phone that is already compromised. Its vault keeps passwords encrypted on users’ devices rather than in a central cloud vault operated by Soclyde. This can reduce scattered copies and help organise unique secrets, but it cannot stop malware from monitoring a device or an accessible secret on it.
Key takeaways
Perseus illustrates how mobile credential theft can extend beyond typed passwords: one documented variant can also browse selected note-taking apps. Small businesses should include work phones in device, permission, and incident management. Find prevention and response steps in our practical infostealer guide.

