s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.tangle_bot

📛 Threat Title

Malware family: TangleBot

Category: TangleBot First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.tangle_bot`. Printable name: TangleBot.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:attack.mitre.org

    TangleBot is SMS malware that was initially observed in September 2021, primarily targeting mobile users in the United States and Canada. TangleBot has used SMS text message lures about COVID-19 regulations and vaccines to trick mobile users into downloading the malware , similar to FluBot Android malware campaigns.

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as TangleBot .

  • web:cryptax.medium.com

    We dig in a malicious sample of Android/ TangleBot of May 2024. TangleBot is also reported as a BankBot, although it is more an Android RAT currently than a banking trojan. It is also known as Medusa, but I prefer not to use this name, as this confuses the Android malware with a Windows ransomware, or with the non-malicious and useful hacking tool Medusa. sha256 ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the TangleBot malware family including references, samples and yara signatures.

  • web:rewterz.com

    Analysis Summary The Medusa banking trojan, also known as TangleBot , has resurfaced in various campaigns targeting countries including France, Italy, the United States, Canada, Spain, the United Kingdom, and Turkey after almost a year of low activity. Tracked since May 2023, this new wave of attacks utilizes more compact variants of the malware that require fewer permissions and include new ...

  • web:www.cleafy.com

    In May 2024, the Cleafy Threat Intelligence team tracked new fraud campaigns involving the Medusa ( TangleBot ) banking trojan, which had been under the radar for almost a year. Medusa is a sophisticated malware family with RAT capabilities discovered in 2020. Its features include a keylogger, screen controls, and the ability to read/write SMS.

  • web:www.cloudmark.com

    Key Takeaways A clever and complicated new SMS malware attack has been discovered in the United States and Canada. This malware , coined TangleBot , can directly obtainpersonal information, control device interaction with apps and overlay screens, and steal account information from financial activities initiated on the device. Overview Cloudmark threat analysts have discovered a new piece of ...

  • web:www.infosecurity-magazine.com

    New fraud campaigns have been discovered involving the Medusa ( TangleBot ) banking Trojan, which had evaded detection for nearly a year. An analysis published by Cleafy researchers last week revealed that this sophisticated malware family , first identified in 2020, has resurfaced with significant ...

  • web:www.proofpoint.com

    A deep dive into insidious new mobile malware . Powerful features and a knack for disguise make Tanglebot a particularly dangerous threat.

  • web:www.techworm.net

    It has been spotted in new campaigns to target users in France, Italy, the United States, Canada, Spain, the United Kingdom, and Turkey. Discovered in 2020, Medusa (also known as TangleBot ) is a sophisticated malware family with Remote Access Trojan (RAT) capabilities. It has now re-emerged with significant changes, including keylogging, screen controls, and the ability to read and write SMS ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.