Sometime between four and seven in the morning, a phone unlocks on its own. The banking app opens, a transfer goes through, and the screen goes dark again. The owner sleeps on, the smartphone lying just inches away.
This is what one of XTN’s banking clients recently observed. Let’s look at how it was possible.
When Malware Takes Control
It’s no secret that mobile channels are the main target of fraud and cyber threats against financial institutions. Malware is a growing part of the problem, especially Remote Access Trojans (RATs) for Android smartphones. RATs are built to take over a device and operate with extreme discretion, often without raising any visible warning for the user or for security systems. They do this by abusing legitimate features of the mobile operating system, such as Android’s Accessibility Services. These tools were created to help people with disabilities or special interaction needs use their devices more easily, for example by reading the content displayed on the screen or automating certain actions. Because they allow such deep interaction with the device, these services have become the preferred entry point for malware seeking remote control.
A recent example is Perseus, a Remote Access Trojan (RAT) built to give attackers remote control of an infected smartphone. Perseus emerged in early 2026 and, like many modern RATs, reaches the device disguised as a sports streaming app. It is installed outside the official stores, taking advantage of a habit already common among users of this kind of app. Once the installation is allowed, the app drops a malicious module onto the device that works through the accessibility services. The malware then takes remote control of the smartphone: it unlocks the device, opens the banking app and makes transfers while the victim notices nothing. Android devices are the ones exposed, because the operating system permits this abuse of accessibility services.
The Limits of Signature-Based Defenses
The Perseus campaign exposed a structural weakness in how many banks defend against malware: their reliance on signature-based detection. A signature is a malware’s fingerprint, a sequence of code that uniquely identifies a file. When a new threat is discovered, analysts extract its signature and add it to a database that security systems check to recognize it. It works like a vaccine that is effective only against virus strains already identified: recognition comes after someone has found the threat.
Changing a small part of the code is enough to make the signature no longer match, and the new version slips past the checks until the database is updated.
That is exactly how Perseus operated. The attackers released new versions in rapid succession, each different enough from the last to evade known signatures. When detection depends on analyzing every variant in advance, the attacker sets the defense’s timeline.
From Signature to Behavior
The anti-malware engine of XTN’s Cognitive Security Platform (CSP)® works on a different principle. Rather than identifying malicious code, it analyzes the app’s behavior: how it moves through the system, which resources it tries to reach, which APIs it uses. Code can be rewritten in a nearly infinite number of ways, but malware built to compromise a banking session still has to intercept credentials, simulate user interaction and execute a transfer.
Those behaviors stay the same no matter how the code changes. Coverage therefore extends beyond a single campaign: the engine automatically recognizes malware families built on the abuse of accessibility services, the technique used by nearly all new-generation mobile RATs.
When Detection Becomes Prevention: A Real Case
This is what happened to one of our banking clients, which learned it was under a Perseus attack from the platform’s detections. The engine had already blocked the malware and every later version automatically, stopping 100% of fraud attempts. The benefit carries over to daily operations: the platform relieves the fraud team of manual checks and analysis, freeing up capacity for higher-value work.
The Value of Zero-Day Detection
XTN’s detection stands out because it happened in zero-day mode. No analyst had to notice the new variants, since the system recognized them on its own. For a bank, this changes where control sits. With signature-based detection, coverage arrives only after a variant has been observed, analyzed and distributed, and during that gap the attacker’s pace determines the level of exposure. With zero-day detection, that window of exposure does not exist.
This capability also goes beyond Perseus: the engine has already intercepted the entire malware family it belongs to, so the next campaign will show up under a different name and a different cover app, and it will already be blocked.
Protecting Beyond a Single Variant
The Perseus case shows how important it is to shift the focus from individual threats to recognizing recurring attack techniques. That is the approach behind the behavioral engine of XTN’s Cognitive Security Platform®, which today protects banks across Europe from RATs like Perseus. Our approach makes it possible to face new campaigns and variants without starting over from the analysis of each individual threat.
Want to see how XTN’s Cognitive Security Platform® protects your bank’s mobile channels? Contact our team by filling out the form below.
