Technology Tips

March 01, 2022

Medusa Android Banking Trojan Steals Sensitive User Information

Written By Securafy Team

There are two new forms of malware spreading rapidly among people with Android devices according to researchers at ThreatFabric. This latest campaign involves the FluBot malware (also known as Cabassous) and the Android banking trojan called Medusa.  What's disturbing about this most recent spate of attacks is that both forms of malware share the same basic infection tactics and delivery infrastructure.

FluBot is one of the most notorious strains of Android malware and can steal passwords, banking details, and other sensitive information from infected devices. It also gains access to the user's list of contacts and uses SMS messages to spread to other devices.

FluBot's success has encouraged imitators. Although Medusa was not created by the same group that authored FluBot, Medusa's authors are following in FluBot's footsteps.

In the case of Medusa it began life as a keylogger. It has been upgraded and can now take screenshots and collect data about how the device is used.  Medusa's authors have even gone so far as to deliver their malicious payload by using poisoned apps bearing the exact same names that FluBot's controllers use.

The researchers at ThreatFabric had this to say about the matter:

"Despite the fact that Medusa is not extremely widespread at the moment, we do see an increase in volume of campaigns and a sufficiently greater number of different campaigns.

Powered with multiple remote access features, Medusa poses a critical threat to financial organisations in targeted regions."

The single best thing users can do to minimize the risk of infection by either of these forms of malware is to install apps from the Google Play store or other authorized and trusted vendors only.  Never install an app via a direct link or from some other website that offers it.  It just isn't worth the risk.

Picture of Securafy Team
About The Author
Our team at Securafy brings you the best tech tips, from how-to guides and troubleshooting advice to software reviews and productivity hacks. We're all about empowering businesses with the tools and knowledge they need to thrive in the digital world. Follow our posts to stay equipped with practical insights that make tech work for you.

Subscribe to our newsletter

Sign up for our FREE "Cyber Security Tip of the Week!" and always stay one step ahead of hackers and cyber-attacks.