Close Menu
Xarkas BlogXarkas Blog
    What's Hot

    Huaweis AI lab denies that one of its Pangu models copied Alibabas Qwen

    July 8, 2025

    This DC Comics Black Label Series Is Perfect for A Sci-Fi Horror Series

    July 8, 2025

    Realme 15 Pro 5G Leaked Render Shows Design Ahead of India Launch

    July 8, 2025
    Facebook X (Twitter) Instagram
    Xarkas BlogXarkas Blog
    • Tech News

      Huaweis AI lab denies that one of its Pangu models copied Alibabas Qwen

      July 8, 2025

      Samsung Galaxy Z Fold 7, Z Flip 7 and Flip 7 FE leak ahead of Unpacked Event 2025

      July 7, 2025

      Apple appeals €500 million EU fine over App Store rules under Digital Markets Act

      July 7, 2025

      Who is Srinivas Narayanan? The tech leader who says AI will turn coders into CEOs

      July 7, 2025

      Painting from 1937 appears to show man using iPhone, but there’s a simpler explanation

      July 7, 2025
    • Mobiles

      Realme 15 Pro 5G Leaked Render Shows Design Ahead of India Launch

      July 8, 2025

      Samsung Galaxy S26 Ultra Said to Get 16GB RAM, Improved Telephoto Lens, More

      July 7, 2025

      Infinix Hot 60 5G+ India Launch Date Set for July 11; to Get a Custom One Tap AI Button

      July 7, 2025

      Tecno Spark 40 Pro+ With MediaTek Helio G200 SoC Launched Alongside Spark 40 Pro and Spark 40

      July 7, 2025

      Google Pixel 6a to Get Mandatory Android 16 Update to Fix Battery Overheating Issues

      July 7, 2025
    • Gaming

      This DC Comics Black Label Series Is Perfect for A Sci-Fi Horror Series

      July 8, 2025

      Last of Us Fan Discovers Surprising Detail Connecting Kaitlyn Dever’s Abby to 11-Year-Old Sitcom

      July 7, 2025

      Death Stranding 2: On The Beach – Official Accolades Trailer

      July 7, 2025

      Open-World Games With The Best Level Design

      July 7, 2025

      How to Beat Lagiacrus in Monster Hunter Wilds

      July 7, 2025
    • SEO Tips
    • PC/ Laptops

      Samsung Smart Monitor M9 With QD-OLED Display Launched in India Alongside Refreshed M8, M7 Models

      July 7, 2025

      HP OmniBook 5, OmniBook 3 Series With Latest AMD and Snapdragon Processors Launched in India

      July 7, 2025

      Apple MacBook Pro With M5 Chip to Launch This Year; 15 Mac Computers in Development: Report

      July 4, 2025

      North Korean Hackers Use NimDoor macOS Malware to Target Web3, Crypto Platforms

      July 3, 2025

      Alienware Area-51, Alienware Aurora Desktops With Latest Intel Core Ultra CPUs Launched in India

      July 2, 2025
    • EV

      The 2025 Porsche Taycan Is Still A Fast-Charging Demon

      July 8, 2025

      Geopolitical Shocks, Rare-Earth Shortages Cloud Auto Sector as June Retail Rises 4.84%

      July 7, 2025

      EVs Power Ahead Despite Rare-Earth Warning, Legacy Players Tighten Grip: Equirus Securities

      July 7, 2025

      Here Are All The EVs And Hybrids That Get A Tax Credit In 2025

      July 7, 2025

      Volvo Will Build Polestar 7 In Slovakia To Dodge China Tariffs

      July 7, 2025
    • Gadget
    • AI
    Facebook
    Xarkas BlogXarkas Blog
    Home - Featured - Medusa Banking Trojan Makes Comeback With Upgrades Targeting Android Devices in Seven Countries
    Featured

    Medusa Banking Trojan Makes Comeback With Upgrades Targeting Android Devices in Seven Countries

    KavishBy KavishSeptember 4, 2024No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Medusa Banking Trojan Makes Comeback With Upgrades Targeting Android Devices in Seven Countries
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    Medusa, a banking trojan that was first identified in 2020, has reportedly returned with several new upgrades that make it more threatening. The new variant of the malware is also said to be targeting more regions than the original version. A cybersecurity firm has detected the trojan active in Canada, France, Italy, Spain, Turkey, the UK, and the US. Medusa primarily attacks Google’s Android operating system, putting smartphone owners at risk. Like any banking trojan, it goes after the banking apps on the device and can even perform on-device frauds.

    New variants of Medusa banking trojan discovered

    Cybersecurity firm Cleafy reports that new fraud campaigns involving the Medusa banking trojan were spotted in May after remaining under the radar for almost a year. Medusa is a type of TangleBot — an Android malware that can infect a device and give the attackers a wide range of control over it. While they can be used for stealing personal information and spying on individuals, Medusa, being a banking trojan, mainly attacks banking apps and steals money from victims.

    The original version of Medusa was equipped with powerful capabilities. For instance, it had the remote access trojan (RAT) capability that allowed it to grant the attacker screen controls and the ability to read and write SMS. It also came with a keylogger and the combination allowed it to perform one of the most dangerous fraud scenarios — on-device fraud, according to the firm.

    However, the new variant is said to be even more dangerous. The cybersecurity firm found that 17 commands that existed in the older malware were removed in the latest Trojan. This was done to minimise the requirement of permissions in the bundled file, raising less suspicion. Another upgrade is that it can set a black screen overlay on the attacked device, which can make the user think the device is locked or powered off, while the trojan performs its malicious activities.

    Threat actors are also reportedly using new delivery mechanisms to infect devices. Earlier, these were spread via SMS links. But now, dropper apps (apps that appear to be legitimate but deploy the malware once installed) are being used to install Medusa under the guise of an update. However, the report highlighted that the malware makers have not been able to deploy Medusa via the Google Play store.

    After being installed, the app flashes messages prompting the user to enable accessibility services to collect the sensor data and keystrokes. The data is then compressed and exported to an encoded C2 server. Once enough information has been collected, the threat actor can use remote access to take control of the device and commit financial fraud.

    Android users are recommended to not click on URLs shared via SMS, messaging apps, or social media platforms by unknown senders. They should also be cautious while downloading apps from untrusted sources, or simply stick to the Google Play store to download and update apps.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Kavish
    • Website

    Related Posts

    Huaweis AI lab denies that one of its Pangu models copied Alibabas Qwen

    July 8, 2025

    This DC Comics Black Label Series Is Perfect for A Sci-Fi Horror Series

    July 8, 2025

    Realme 15 Pro 5G Leaked Render Shows Design Ahead of India Launch

    July 8, 2025

    The 2025 Porsche Taycan Is Still A Fast-Charging Demon

    July 8, 2025

    Samsung Galaxy Z Fold 7, Z Flip 7 and Flip 7 FE leak ahead of Unpacked Event 2025

    July 7, 2025

    Apple appeals €500 million EU fine over App Store rules under Digital Markets Act

    July 7, 2025
    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Huaweis AI lab denies that one of its Pangu models copied Alibabas Qwen

    July 8, 2025

    This DC Comics Black Label Series Is Perfect for A Sci-Fi Horror Series

    July 8, 2025

    Realme 15 Pro 5G Leaked Render Shows Design Ahead of India Launch

    July 8, 2025

    The 2025 Porsche Taycan Is Still A Fast-Charging Demon

    July 8, 2025
    About Us
    About Us

    Email Us: info@xarkas.com

    Facebook Pinterest
    © 2025 . Designed by Xarkas Technologies.
    • Home
    • Mobiles
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.