A highly targeted banking trojan that scans your personal notes for passwords, recovery phrases, and financial data.

What Perseus Looks For in Your Notes

Perseus is a banking trojan that treats the notes app on an Android device as a vault worth opening. Many people store bank logins, card details, one-time backup codes, and cryptocurrency recovery phrases in plain text because notes feel private and convenient. A trojan built for that habit does not need to break encryption on every app you use. It only needs access to the notes store, then it can search for patterns that look like secrets: long random word lists, account numbers, PINs written next to bank names, and phrases that match how people label passwords.

Because the attack is highly targeted, the malware is less about noisy mass infection and more about reaching devices where notes are likely to hold financial data. Once it can read those entries, the rest of the crime is familiar: use the recovered credentials, reset accounts with seed phrases, or drain wallets and bank apps that rely on the same secrets you wrote down “just for yourself.”

Why Notes Are an Attractive Target

Notes sit in a weak middle ground. They are not a password manager with autofill isolation and strong vault encryption by default, yet people treat them as one. Android notes can sync across devices, appear in search, and remain readable to any process that gains the right permissions or abuse path. A banking trojan that can scan notes turns everyday convenience into a single point of failure: one readable file or database can expose years of accumulated logins and recovery material.

Recovery phrases are especially damaging. Unlike a password you can change after a breach, a seed phrase is often the permanent key to a wallet. If Perseus finds that phrase in a note, ownership of the asset can transfer without the banking app even opening on the victim’s screen. The same logic applies to backup codes and security-question answers stored next to account names—material designed for account recovery becomes the attacker’s recovery path instead.

Practical Steps That Reduce Risk

Assume any plain-text note can be read by malware that gains a foothold. Move secrets out of notes and into tools built for secrets: a password manager for logins, and offline, never-photographed storage for recovery phrases. Do not paste seed phrases, full card numbers, or banking PINs into notes “temporarily.” Temporary storage on a phone often becomes permanent backup in cloud sync.

  • Uninstall unused apps and avoid sideloading banking-related APKs outside trusted store channels.
  • Review app permissions that claim accessibility, overlay, SMS, or broad storage access without a clear need.
  • Keep system and bank apps updated so known abuse paths close faster.
  • Search your notes for words like password, seed, recovery, PIN, and bank names; delete or relocate anything sensitive.
  • Enable device lock with a strong PIN or biometrics, and treat a lost or shared unlocked phone as a full notes breach.

If you already used notes for financial data, treat those secrets as exposed until you rotate them. Change passwords, regenerate recovery codes where the service allows it, and move wallets or accounts off any seed phrase that ever lived in plain text on the device.

How to Think About Banking Trojans Going Forward

Perseus is a reminder that modern banking malware does not only chase login screens. It hunts the places users park the keys to those screens. Defending against that class of threat is less about memorizing one malware family name and more about reducing what a single compromised notes surface can reveal. Keep financial secrets out of free-form text, limit what untrusted software can read, and treat recovery phrases as offline assets—not phone content. Those habits blunt Perseus and the next trojan that copies the same idea.

Automate Your Content with AI Video Generator

Try it Free →