Friday, May 23, 2025
HomeAndroidNew Medusa RAT Attacking Android Devices to Steal SMS & Screen Controls

New Medusa RAT Attacking Android Devices to Steal SMS & Screen Controls

Published on

SIEM as a Service

Follow Us on Google News

A new variant of the Medusa malware family was discovered disguised as a “4K Sports” app, which exhibits changes in command structure and capabilities compared to previous versions. 

Researchers believe these changes are aimed at improving efficiency and strengthening the botnet.

The MaaS model used by Medusa allows for adaptations based on various factors, such as new affiliates seeking less detectable variants to target unexplored regions. 

- Advertisement - Google News
Sports 4K Activities
Sports 4K Activities

The Medusa banking Trojan, first discovered in 2020, grants attackers remote access to devices through VNC and accessibility services, allowing them to perform real-time screen sharing, steal keystrokes, and launch overlay attacks for on-device fraud (ODF) such as account takeover (ATO). 

Medusa communicates with the attacker’s C2 server through a web socket connection, fetching the URL dynamically from social media platforms like Telegram for obfuscation and resilience against takedowns.

The malware also utilizes backup channels on social media for additional communication redundancy. 

Key-logging in Action
Key-logging in Action

A recent resurgence of Medusa malware campaigns, since July 2023, utilizes social engineering (smishing) to deliver droppers that side-load the malware onto Android devices in targeted countries (CA, ES, FR, IT, UK, US, TK). 

Scan Your Business Email Inbox to Find Advanced Email Threats - Try AI-Powered Free Threat Scan

This new variant leverages on-device fraud (ODF) but specific cash-out methods and transfer amounts remain unknown, while Medusa exhibits adaptability through its backend infrastructure, which can support multiple botnets with distinct functionalities. 

Cleafy discovered five active botnets that were distinguished from one another based on the types of decoys, distribution strategies, and locations that were targeted. 

 Most-used icons and names in recent Medusa campaigns
 Most-used icons and names in recent Medusa campaigns

Two Medusa botnet clusters were identified; where Cluster 1 targets Turkey, the US, and Canada and uses traditional phishing tactics, while Cluster 2 targets Europe and uses droppers besides phishing, as both clusters are reducing requested permissions to evade detection. 

Early campaigns requested permissions for cameras, microphones, locations, etc., but recent campaigns only request permissions for core functionalities like accessibility, SMS, internet, foreground service, and package management, which makes them stealthier and harder to detect.  

Comparison of permissions required in early and recent campaigns
Comparison of permissions required in early and recent campaigns

Researchers identified a new variant of Medusa malware with a streamlined command set, and 17 commands from the previous version were removed to reduce its footprint and improve stealth. 

Command “setoverlay” in action
Command “setoverlay” in action

Five new commands were introduced, including taking screenshots, uninstalling apps, and controlling the device screen with a black overlay, which allows attackers to mask malicious activities and potentially steal sensitive information. 

Some functionalities requiring permissions (e.g., sending SMS, getting contacts) are still present in the code but blocked by the system without permission grants, which suggests that the malware is adaptable and can be easily modified for future campaigns. 

Free Webinar! 3 Security Trends to Maximize MSP Growth -> Register For Free

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Latest articles

TAG-110 Hackers Deploy Malicious Word Templates in Targeted Attacks

The Russia-aligned threat actor TAG-110, also linked to UAC-0063 and APT28 (BlueDelta) with medium...

Winos 4.0 Malware Masquerades as VPN and QQBrowser to Target Users

A sophisticated malware campaign deploying Winos 4.0, a memory-resident stager, has been uncovered by...

NETGEAR Router Flaw Allows Full Admin Access by Attackers

A severe authentication bypass vulnerability (CVE-2025-4978) has been uncovered in NETGEAR’s DGND3700v2 wireless routers,...

Operation Endgame Crushes DanaBot Malware, Shuts Down 150 C2 Servers and Halts 1,000 Daily Attacks

Operation Endgame II has delivered a devastating strike against DanaBot, a notorious malware that...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

TAG-110 Hackers Deploy Malicious Word Templates in Targeted Attacks

The Russia-aligned threat actor TAG-110, also linked to UAC-0063 and APT28 (BlueDelta) with medium...

Winos 4.0 Malware Masquerades as VPN and QQBrowser to Target Users

A sophisticated malware campaign deploying Winos 4.0, a memory-resident stager, has been uncovered by...

NETGEAR Router Flaw Allows Full Admin Access by Attackers

A severe authentication bypass vulnerability (CVE-2025-4978) has been uncovered in NETGEAR’s DGND3700v2 wireless routers,...