Netskope Threat Labs

MEDUSA

ATP Sandbox Adv. HeuristicsAV

Medusa is an Android banking trojan that steals credentials from financial applications and performs overlay attacks that display fake login screens over legitimate apps. It abuses accessibility services to read screen content, intercept notifications, and defeat text based verification codes, and its operators rent it out as a service to other criminal crews. Campaigns against banks across Europe and North America have grown steadily, and its modular updates continue to expand its data theft features.

First seen
February 2023
Last seen
October 2026

4 techniques across 2 tactics.

TA0005 Stealth

TA0008 Lateral Movement

Alert Name
Android.Trojan.Medusa
DeepScan:Generic.PY.Medusa.A.FFFFFFFE
Document-HTML.Ransomware.Medusa
Dropped:Generic.Linux.Medusa.C.C56B64CB
Dump:Generic.Linux.Medusa.D.FFFFFFFE
Dump:Generic.PY.Medusa.A.FFFFFFFE
Gen:Heur.Mint.FL.Medusa.1
Generic.Linux.Medusa.A.03685BD9
Generic.Linux.Medusa.A.1C836CD4
Generic.Linux.Medusa.A.1F4B88D3