Search

Medusa Banking Trojan Makes Comeback With Upgrades Targeting Android Devices in Seven Countries

Medusa can now perform on-device fraud targeted at users with Android smartphones.

Advertisement
Highlights
  • Medusa is a banking trojan that can reportedly write and read SMS
  • The malware is said to be active since July 2023
  • Medusa is said to have had multiple upgrades over the 2020 variant
Medusa Banking Trojan Makes Comeback With Upgrades Targeting Android Devices in Seven Countries

The malware is reportedly targeting several European and North American countries

Photo Credit: Pexels/Sora Shimazaki

Medusa, a banking trojan that was first identified in 2020, has reportedly returned with several new upgrades that make it more threatening. The new variant of the malware is also said to be targeting more regions than the original version. A cybersecurity firm has detected the trojan active in Canada, France, Italy, Spain, Turkey, the UK, and the US. Medusa primarily attacks Google's Android operating system, putting smartphone owners at risk. Like any banking trojan, it goes after the banking apps on the device and can even perform on-device frauds.

New variants of Medusa banking trojan discovered

Cybersecurity firm Cleafy reports that new fraud campaigns involving the Medusa banking trojan were spotted in May after remaining under the radar for almost a year. Medusa is a type of TangleBot — an Android malware that can infect a device and give the attackers a wide range of control over it. While they can be used for stealing personal information and spying on individuals, Medusa, being a banking trojan, mainly attacks banking apps and steals money from victims.

The original version of Medusa was equipped with powerful capabilities. For instance, it had the remote access trojan (RAT) capability that allowed it to grant the attacker screen controls and the ability to read and write SMS. It also came with a keylogger and the combination allowed it to perform one of the most dangerous fraud scenarios — on-device fraud, according to the firm.

However, the new variant is said to be even more dangerous. The cybersecurity firm found that 17 commands that existed in the older malware were removed in the latest Trojan. This was done to minimise the requirement of permissions in the bundled file, raising less suspicion. Another upgrade is that it can set a black screen overlay on the attacked device, which can make the user think the device is locked or powered off, while the trojan performs its malicious activities.

Threat actors are also reportedly using new delivery mechanisms to infect devices. Earlier, these were spread via SMS links. But now, dropper apps (apps that appear to be legitimate but deploy the malware once installed) are being used to install Medusa under the guise of an update. However, the report highlighted that the malware makers have not been able to deploy Medusa via the Google Play store.

After being installed, the app flashes messages prompting the user to enable accessibility services to collect the sensor data and keystrokes. The data is then compressed and exported to an encoded C2 server. Once enough information has been collected, the threat actor can use remote access to take control of the device and commit financial fraud.

Android users are recommended to not click on URLs shared via SMS, messaging apps, or social media platforms by unknown senders. They should also be cautious while downloading apps from untrusted sources, or simply stick to the Google Play store to download and update apps.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

 
Show Full Article
Please wait...
Advertisement
Popular Mobile Brands
  1. OTT Releases of the Week: Rana Naidu Season 2, The Traitors, and More
  2. Sony Announces Limited-Period Discount on Audio Products in India
  3. iPhone 17 Pro, iPhone 17 Pro Max Alleged Geekbench Listing Leaked
  4. OnePlus Nord 5 Allegedly Spotted on Geekbench With This Chipset
  5. Realme Narzo 80 Lite 5G to Launch in India on This Day
  6. Truecaller's New Feature Will Verify Business Calls to Stop Online Scams
  7. iQOO Z10 Lite 5G Battery Capacity Confirmed Ahead of India Launch
  8. Poco F7 Spotted on Geekbench With Snapdragon 8s Gen 4, 12GB of RAM
  9. The Summer I Turned Pretty Season 3 OTT Release Date: When and Where to Watch Final Season Online?
  10. Infinix GT 30 Pro 5G Goes on Sale in India: See Launch Offers
  1. Apple to Release Advanced Siri for iPhone With iOS 26.4 Update in Spring 2026: Report
  2. OTT Releases of the Week (June 9 - June 15): Rana Naidu Season 2, The Traitors, Alappuzah Gymkhana, and More
  3. Hubble Finds Cosmic Dust Coating Uranus’ Moons, Not Radiation Scars
  4. New Theory Challenges Black Hole Singularities, But Critics Raise Red Flags
  5. Solar Orbiter Captures First-Ever Close-Up of Sun’s South Pole, Revealing Magnetic Field Chaos
  6. The Summer I Turned Pretty Season 3 OTT Release Date: When and Where to Watch Final Season Online?
  7. Mokshapatam Hindi OTT Release: Where to Watch it Online?
  8. Titan: The OceanGate Disaster Now Streaming on Netflix: What You Need to Know
  9. Stellar Blade Becomes Sony's Biggest Single-Player Steam Launch Ever a Day After PC Release
  10. Microsoft 365 Copilot Vulnerable to Zero-Click EchoLeak Exploit, Cybersecurity Researchers Say
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »