216.73.217.22

DTO malware that takes notes

· Published 19/03/2026 11:00 · Modified 19/03/2026 13:54

Export JSON

Essential information

Published
19/03/2026 11:00
Modified
19/03/2026 13:54
Tags
2026-03-19 accessibility service android anti-analysis cerberus dto ermac iptv klopatra medusa notes monitoring overlay attacks perseus phoenix remote-control
Related entities
3 observables, 1 intrusion sets (apt), 6 malware, 7 others

Description

is a new threat that builds upon earlier malware families like and . It enables real-time monitoring and interaction with infected devices through Accessibility-based remote sessions, allowing full Device Takeover. The malware focuses on extracting high-value personal information, including monitoring user notes. It employs strong measures to evade detection. is primarily distributed through applications, targeting users in Turkey and Italy. Its capabilities include , keylogging, and systematic exploration of note-taking apps. The malware performs extensive environment checks to detect analysis conditions and assess device risk. represents the ongoing evolution of mobile malware, adapting to remain effective in an increasingly secure mobile environment.

External references