Android spyware, Flubot, has been spreading like wildfire for a year now, has teamed up with Medusa, another mobile malware.
According to ThreatFabric, Medusa is now being disseminated via the same SMS-phishing technology as Flubot, which leads to high campaigns simultaneously.
According to ThreatFabric experts, Medusa loves the cut of Flubot’s jib. ThreatFabric’s threat intelligence suggests that Medusa follows with almost the same program names, package names, and identical icons.
In less than a month, this distribution strategy allowed Medusa to reach over 1.5K infected devices in one botnet, disguised as DHL.
That’s just for a single botnet. Medusa has numerous botnets running multiple campaigns, according to ThreatFabric.
When it comes to geography, Medusa seems more like an equal-opportunity threat in contrast to Flubot, which is mostly found in Europe. Clients from Canada, Turkey, and the United States have been targeted in recent operations.
According to ThreatFabric, considering the popularity of these types of apps and Flubot’s strong focus on distribution strategies, this might be the main MO driving this new Notification Direct Reply Abuse.
#Phishing #flubot #Spyware #Cybersecurity #News #Android

Share: