New Medusa malware variants target Android users in seven countries
ID: 065cf823-3597-57d8-b1f7-bf04dbfe6d70
STIX ID: report--065cf823-3597-57d8-b1f7-bf04dbfe6d70
Feed Name: Bleeping Computer
Medusa (TangleBot), an Android banking trojan, has re-emerged in mid-2023 with more compact variants that request fewer permissions but retain Accessibility Service abuse, SMS manipulation, contact access, and new commands including black-screen overlays and screenshot capture. Cleafy observed 24 campaigns across five botnets targeting several countries via smishing droppers (fake apps), with C2 URLs retrieved from social media; the changes increase stealth and potential financial theft even though droppers were not observed on Google Play.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
