Close Menu
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On

Meta Accused of Torrenting Porn to Advance Its Goal of AI ‘Superintelligence’

19 September 2025

How Energy-Generating Sidewalks Work

19 September 2025

EVs Have Gotten Too Powerful

19 September 2025
Facebook X (Twitter) Instagram
Just In
  • Meta Accused of Torrenting Porn to Advance Its Goal of AI ‘Superintelligence’
  • How Energy-Generating Sidewalks Work
  • EVs Have Gotten Too Powerful
  • Jensen Huang Wants You to Know He’s Getting a Lot Out of the ‘Fantastic’ Nvidia-Intel Deal
  • These Are the 15 New York Officials ICE and NYPD Arrested in Manhattan
  • Vaccine Panel Stacked by RFK Jr. Recommends Delaying MMRV Immunization
  • Move Aside, Chatbots: AI Humanoids Are Here
  • Brendan Carr Isn’t Going to Stop Until Someone Makes Him
Facebook X (Twitter) Instagram Pinterest Vimeo
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release
Subscribe
Best in TechnologyBest in Technology
Home » Medusa Banking Trojan Makes Comeback With Upgrades Targeting Android Devices in Seven Countries
Phones

Medusa Banking Trojan Makes Comeback With Upgrades Targeting Android Devices in Seven Countries

News RoomBy News Room28 June 20243 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email

Medusa, a banking trojan that was first identified in 2020, has reportedly returned with several new upgrades that make it more threatening. The new variant of the malware is also said to be targeting more regions than the original version. A cybersecurity firm has detected the trojan active in Canada, France, Italy, Spain, Turkey, the UK, and the US. Medusa primarily attacks Google’s Android operating system, putting smartphone owners at risk. Like any banking trojan, it goes after the banking apps on the device and can even perform on-device frauds.

New variants of Medusa banking trojan discovered

Cybersecurity firm Cleafy reports that new fraud campaigns involving the Medusa banking trojan were spotted in May after remaining under the radar for almost a year. Medusa is a type of TangleBot — an Android malware that can infect a device and give the attackers a wide range of control over it. While they can be used for stealing personal information and spying on individuals, Medusa, being a banking trojan, mainly attacks banking apps and steals money from victims.

The original version of Medusa was equipped with powerful capabilities. For instance, it had the remote access trojan (RAT) capability that allowed it to grant the attacker screen controls and the ability to read and write SMS. It also came with a keylogger and the combination allowed it to perform one of the most dangerous fraud scenarios — on-device fraud, according to the firm.

However, the new variant is said to be even more dangerous. The cybersecurity firm found that 17 commands that existed in the older malware were removed in the latest Trojan. This was done to minimise the requirement of permissions in the bundled file, raising less suspicion. Another upgrade is that it can set a black screen overlay on the attacked device, which can make the user think the device is locked or powered off, while the trojan performs its malicious activities.

Threat actors are also reportedly using new delivery mechanisms to infect devices. Earlier, these were spread via SMS links. But now, dropper apps (apps that appear to be legitimate but deploy the malware once installed) are being used to install Medusa under the guise of an update. However, the report highlighted that the malware makers have not been able to deploy Medusa via the Google Play store.

After being installed, the app flashes messages prompting the user to enable accessibility services to collect the sensor data and keystrokes. The data is then compressed and exported to an encoded C2 server. Once enough information has been collected, the threat actor can use remote access to take control of the device and commit financial fraud.

Android users are recommended to not click on URLs shared via SMS, messaging apps, or social media platforms by unknown senders. They should also be cautious while downloading apps from untrusted sources, or simply stick to the Google Play store to download and update apps.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleFallout 5: release date speculation, rumors, and news
Next Article Amazon Is Investigating Perplexity Over Claims of Scraping Abuse

Related Articles

Phones

Vivo V60 Launched in India With Snapdragon 7 Gen 4 SoC, 50-Megapixel Telephoto Camera: Price, Features

12 August 2025
Phones

OnePlus Said to Be Testing Display With 165Hz Refresh Rate; Might Arrive on Midrange Smartphone

12 August 2025
Phones

Flipkart Independence Day Sale 2025 Begins Tomorrow: Deals on iPhone 16, Samsung Galaxy S24, and More

12 August 2025
Phones

Honor X7c 5G Specifications Teased Ahead of India Launch; Will Feature 5,200mAh Battery, Snapdragon 4 Gen 2 SoC

12 August 2025
Phones

Samsung Galaxy A07 Design, Colour Options, Key Features Leaked; Tipped to Get Six Android OS Upgrades

12 August 2025
Phones

Realme P4 Series Key Specifications Confirmed Ahead of Launch in India on August 20

12 August 2025
Demo
Top Articles

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024105 Views

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views

5 laptops to buy instead of the M4 MacBook Pro

17 November 202492 Views

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Latest News
News

Vaccine Panel Stacked by RFK Jr. Recommends Delaying MMRV Immunization

News Room19 September 2025
News

Move Aside, Chatbots: AI Humanoids Are Here

News Room19 September 2025
News

Brendan Carr Isn’t Going to Stop Until Someone Makes Him

News Room19 September 2025
Most Popular

The Spectacular Burnout of a Solar Panel Salesman

13 January 2025129 Views

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024105 Views

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views
Our Picks

Jensen Huang Wants You to Know He’s Getting a Lot Out of the ‘Fantastic’ Nvidia-Intel Deal

19 September 2025

These Are the 15 New York Officials ICE and NYPD Arrested in Manhattan

19 September 2025

Vaccine Panel Stacked by RFK Jr. Recommends Delaying MMRV Immunization

19 September 2025

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us
© 2025 Best in Technology. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.