logo

New Medusa malware variants target Android users in seven countries

ID: 065cf823-3597-57d8-b1f7-bf04dbfe6d70

STIX ID: report--065cf823-3597-57d8-b1f7-bf04dbfe6d70

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-06-25

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Medusa (TangleBot), an Android banking trojan, has re-emerged in mid-2023 with more compact variants that request fewer permissions but retain Accessibility Service abuse, SMS manipulation, contact access, and new commands including black-screen overlays and screenshot capture. Cleafy observed 24 campaigns across five botnets targeting several countries via smishing droppers (fake apps), with C2 URLs retrieved from social media; the changes increase stealth and potential financial theft even though droppers were not observed on Google Play.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.