logo

New Medusa Android Trojan Targets Banking Users Across 7 Countries

ID: b4227466-dba8-5131-9474-918208643c67

STIX ID: report--b4227466-dba8-5131-9474-918208643c67

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-06-26

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers observed updated Medusa (TangleBot) Android banking trojan campaigns active since 2023 and seen in May 2024, targeting users in multiple countries. New features include a full-screen/black-screen overlay, remote uninstall, reduced permission requests (while abusing accessibility APIs), and distribution via dropper apps and phishing; C2 retrieval via Telegram/X was also observed. Related Android threats (SpyMax, Cerberus) and delivery lures (fake browser/Telegram updates) are discussed, highlighting evolving tactics to steal credentials and exfiltrate sensitive device data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.