SOCLYDE logo
Current languageEN
Cybersecurity newsAndroidBanking trojanCredential theft

Perseus: android malware that scans notes

Android malware Perseus masquerades as an IPTV app and can browse selected notes. What small businesses should know about the risk.

By Soclyde Editorial Team

Android phone showing a streaming app beside a notebook in a small business office

In summary

  • ThreatFabric documented Perseus, Android malware distributed under the guise of IPTV apps.
  • A studied English-language variant can open selected note-taking apps and browse their contents using Accessibility services.
  • Businesses should include phones used for email or authentication in their device inventory and incident procedure.

Explore next

Soclyde resources

Article contents

On March 19, 2026, security research firm ThreatFabric described Perseus, Android malware designed to take over devices and facilitate financial fraud. The analysed samples were distributed as streaming or IPTV apps through unofficial websites and stores.

One capability drew particular attention: an English-language variant can search for selected note-taking apps, open them, and browse their contents. For a business, a work phone can therefore become an exposure point for credentials or business information copied onto it.

What ThreatFabric observed

Perseus builds on earlier Android malware families and includes remote-control capabilities. ThreatFabric describes its use of Accessibility services to interact with the phone’s interface, observe the screen, and perform actions. These capabilities can let operators access banking apps or other services open on the device.

The note-scanning behaviour is specific to the English-language variant studied. A command called scan_notes checks for several predefined apps, including Google Keep, Samsung Notes, Xiaomi Notes, Evernote, ColorNote, and Simple Notes. ThreatFabric says the package identifier associated with OneNote in the sample is incorrect. Researchers also identified a Turkish variant with different functionality.

Why notes matter to business teams

Notes may contain passwords, recovery codes, financial information, or other details saved for convenience. If malware can read the screen and control apps, simply keeping secrets organised in notes does not protect copies stored there.

ThreatFabric’s findings describe specific samples; they do not show that every note-taking app or every Android phone is exposed. The report lists targeted institutions in several countries, including two in France, but by itself does not establish that a French organisation was compromised.

The IPTV lure and APK installation

Observed campaigns presented the malware as a streaming app, including apps for sports content. The installation flow encouraged people to download an APK from an unofficial channel and grant permissions that let the software act on the interface.

This fits a series of Android campaigns documented by ThreatFabric: other banking malware, such as Massiv, was also distributed as IPTV apps, while StreamRat used ads to promote fake streaming apps. These are separate malware families. Their common thread is the streaming lure and risky installation, not an identical ability to read notes.

Practical steps for small businesses

Include work phones in the inventory of devices that access email, business apps, or authentication factors. To reduce exposure:

  • install apps from trusted sources and decline APKs prompted by ads, messages, or unfamiliar websites;
  • keep Android and apps up to date, and leave built-in protections enabled;
  • review requests for Accessibility access carefully. These services are legitimate, but an app enabling them without an obvious need should be checked;
  • avoid copying business secrets into ordinary notes or shared files;
  • document whom to contact and how to revoke sessions if a phone looks suspicious.

Security options vary by Android version, device maker, and configuration. An Accessibility permission is not, by itself, proof of infection: the app and its reason for requesting access matter.

If a phone looks suspicious

Alert the IT owner and follow the company’s incident procedure. Do not only delete the app if the phone granted sensitive access or was used to sign in to work accounts. From a clean device, revoke active sessions and replace potentially exposed secrets, starting with email and accounts that can reset other access.

Preserve the phone so it can be examined under the organisation’s process. An immediate factory reset may erase useful evidence. If the team lacks incident-response expertise, contact a specialist provider.

How Soclyde fits

Soclyde does not detect Perseus or protect an Android phone that is already compromised. Its vault keeps passwords encrypted on users’ devices rather than in a central cloud vault operated by Soclyde. This can reduce scattered copies and help organise unique secrets, but it cannot stop malware from monitoring a device or an accessible secret on it.

Key takeaways

Perseus illustrates how mobile credential theft can extend beyond typed passwords: one documented variant can also browse selected note-taking apps. Small businesses should include work phones in device, permission, and incident management. Find prevention and response steps in our practical infostealer guide.

Frequently asked questions

Does Perseus affect every Android note-taking app?

No. ThreatFabric describes an English-language variant that looks for a predefined list of apps. Microsoft OneNote appears with an incorrect package identifier, limiting that target as described. Researchers also observed a Turkish variant with different functionality.

Is every IPTV app dangerous?

No. The report concerns malicious apps masquerading as IPTV services and distributed through unofficial channels. It does not establish that IPTV apps in general are malicious.

What should we do if a work phone installed a suspicious APK?

Alert the IT owner and follow the organisation’s incident procedure. From a clean device, revoke sessions and replace potentially exposed secrets. Preserve the phone for analysis instead of only deleting the app.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading