Topics Tools Books & Guides Talk to Securafy

Knowledge Hub / IT Operations

IT Operations

Medusa Android Banking Trojan Steals Sensitive User Information

Medusa Android Banking Trojan Steals Sensitive User Information

Randy Hall By Randy Hall Updated Jul 2024 2 min read Share

There are two new forms of malware spreading rapidly among people with Android devices according to researchers at ThreatFabric. This latest campaign involves the FluBot malware (also known as Cabassous) and the Android banking trojan called Medusa.  What's disturbing about this most recent spate of attacks is that both forms of malware share the same basic infection tactics and delivery infrastructure.

FluBot is one of the most notorious strains of Android malware and can steal passwords, banking details, and other sensitive information from infected devices. It also gains access to the user's list of contacts and uses SMS messages to spread to other devices.

FluBot's success has encouraged imitators. Although Medusa was not created by the same group that authored FluBot, Medusa's authors are following in FluBot's footsteps.

In the case of Medusa it began life as a keylogger. It has been upgraded and can now take screenshots and collect data about how the device is used.  Medusa's authors have even gone so far as to deliver their malicious payload by using poisoned apps bearing the exact same names that FluBot's controllers use.

The researchers at ThreatFabric had this to say about the matter:

"Despite the fact that Medusa is not extremely widespread at the moment, we do see an increase in volume of campaigns and a sufficiently greater number of different campaigns.

Powered with multiple remote access features, Medusa poses a critical threat to financial organisations in targeted regions."

The single best thing users can do to minimize the risk of infection by either of these forms of malware is to install apps from the Google Play store or other authorized and trusted vendors only.  Never install an app via a direct link or from some other website that offers it.  It just isn't worth the risk.

Join The Conversation

Have a question or perspective on this topic? Add it below.

Randy Hall

About The Author

Randy Hall · CEO & Founder

Randy Hall is the CEO and Founder of Securafy, with decades of experience helping organizations make smarter, safer decisions about technology.

A frequent speaker and instructor at national IT events, Randy has advised thousands of organizations, from startups and SMBs to large enterprises and U.S. government entities, on secure, practical technology adoption. He writes about the decisions business leaders are often expected to make without enough context, including cybersecurity, compliance, AI, cyber insurance, IT strategy, and business resilience.

Outside the office, you’ll often find Randy on Lake Erie enjoying time on his 38-foot Chris-Craft.

Writes about: Cybersecurity strategy, compliance, AI security, business resilience, cyber insurance, SMB risk, IT leadership

More From This Author →

Get Practical Cybersecurity Field Notes

Monthly cybersecurity, compliance, and IT strategy updates from Securafy, written for business owners who need clear next steps.

  • Practical security tips from our Cyber Security Drip series
  • The Securafy Times, our monthly roundup on compliance and IT strategy
  • Occasional updates on new tools, guides, and research
  • No spam — unsubscribe anytime