New Medusa Android Trojan Targets Banking Users Across 7 Countries
ID: b4227466-dba8-5131-9474-918208643c67
STIX ID: report--b4227466-dba8-5131-9474-918208643c67
Feed Name: The Hacker News
Cybersecurity researchers observed updated Medusa (TangleBot) Android banking trojan campaigns active since 2023 and seen in May 2024, targeting users in multiple countries. New features include a full-screen/black-screen overlay, remote uninstall, reduced permission requests (while abusing accessibility APIs), and distribution via dropper apps and phishing; C2 retrieval via Telegram/X was also observed. Related Android threats (SpyMax, Cerberus) and delivery lures (fake browser/Telegram updates) are discussed, highlighting evolving tactics to steal credentials and exfiltrate sensitive device data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
