Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallA June 20, 2024 investigation by Cleafy identified five Medusa Android botnets associated with 24 campaign entries targeting users in Canada, Spain, France, Italy, the United Kingdom, the United States and Turkey. The disclosure describes observed activity beginning in July 2023 and investigated in May and June 2024; it is not, by itself, evidence of a newly discovered August 2026 outbreak.
These campaigns used phishing, smishing, fake Chrome or Android updates, video and premium-service decoys, and dropper applications. The malware is an Android banking trojan with remote-access capabilities that can enable on-device fraud.
What Medusa is
This Medusa is an Android banking trojan with RAT (remote-access trojan) capabilities, not the similarly named Medusa ransomware used against Windows and enterprise environments. Cleafy says the Android malware was first identified in 2020 and is also known as TangleBot. Its capabilities include keylogging, screen control, SMS reading and writing, dynamic overlays, remote interaction and abuse of Android Accessibility Services.
That combination supports on-device fraud (ODF): criminals can operate through a victim’s already authenticated phone rather than merely stealing a password. A compromised device may contain logged-in banking sessions, trusted-device status, SMS authentication messages, payment apps and contact data. Screen control and Accessibility access can let an operator observe or manipulate activity while the legitimate banking app is running. Cleafy describes account takeover and on-device fraud as the core criminal objectives.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minute#1 Best Overall
- SPEED-OPTIMIZED, CROSS-PLATFORM PROTECTION: World-class antivirus security and cyber protection for Windows (Windows 7 with Service Pack 1, Windows 8, Windows 8.1, Windows 10, and Windows 11), Mac OS (Yosemite 10.10 or later), iOS (11.2 or later), and Android (5.0 or later). Organize and keep your digital life safe from hackers
- SAFE ONLINE BANKING: A unique, dedicated browser secures your online transactions; Our Total Security product also includes 200MB per day of our new and improved Bitdefender VPN
- ADVANCED THREAT DEFENSE: Real-Time Data Protection, Multi-Layer Malware and Ransomware Protection, Social Network Protection, Game/Movie/Work Modes, Microphone Monitor, Webcam Protection, Anti-Tracker, Phishing, Fraud, and Spam Protection, File Shredder, Parental Controls, and more
- ECO-FRIENDLY PACKAGING: Your product-specific code is printed on a card and shipped inside a protective cardboard sleeve. Simply open packaging and scratch off security ink on the card to reveal your activation code. No more bulky box or hard-to-recycle discs. PLEASE NOTE: Product packaging may vary from the images shown, however the product is the same.
Source: Cleafy’s technical report.
Where the 24 campaigns operated
| Country | Code in Cleafy report |
|---|---|
| Canada | CA |
| Spain | ES |
| France | FR |
| Italy | IT |
| United Kingdom | UK |
| United States | US |
| Turkey | TK |
The geographic list describes campaign targeting, not a measured victim count or equal exposure in every country. Cleafy’s cluster analysis found a stronger concentration in Turkey for the AFETZEDE, ANAKONDA, PEMBE and TONY botnets, with some activity involving Canada and the United States. The separate UNKN botnet focused mainly on European users, particularly in France and Italy. Spain and the United Kingdom appear in the overall target summary, although the report provides less operational detail about those locations.
Five botnets versus 24 campaigns
A botnet is an operational grouping controlled through related backend infrastructure. A campaign is an individual distribution effort, lure or tag. Thus, five botnets and 24 campaign entries describe two levels of the same operation; they are not contradictory, and they do not represent 24 malware families.
Cluster 1: AFETZEDE, ANAKONDA, PEMBE and TONY
- Primarily Turkey-focused, with some Canadian and US activity.
- Relied largely on phishing or smishing and overlapping decoys, campaign names and command-and-control infrastructure.
Cluster 2: UNKN
- Focused mainly on European targets, especially France and Italy.
- Experimented with dropper applications and fake-update workflows instead of relying only on phishing.
Cleafy reported that a command-and-control URL could be fetched dynamically from public profiles on services including Telegram, Twitter and ICQ, making infrastructure changes easier for operators.
Rank #2
- THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
- PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
- SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
- GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
- MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.
The campaign entries and decoys
The following table condenses the appendix. Dates are first-seen dates reported by Cleafy; two separate UNKN entries carry the label FFPR, so counting unique names would undercount the 24 entries.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →| Botnet | Campaign labels and first-seen dates | Decoy applications |
|---|---|---|
| PEMBE | Guncelke (Jul 5, 2023); SONVERS (Jul 31); reklam (Aug 8); reklam2 (Aug 15); AvastV1 (Sep 25); 17 Agustos reklami (Oct 24); reklam 3 (Oct 24); propeller android (Mar 20, 2024); Mart19 (Mar 20) | Aidat İadesi; YouTube Premium; Cimer Aidat İadesi; İnat TV PRO Video Oynatici; Avast Premium; İnat TV Video Oynatici; İnat TV PRO; Android 14 Guncellemesi; İnat TV Video Oynaticisi |
| UNKN | PUROFR1 (Jul 22, 2023); TestTag (Jul 22); PURO1 (Jul 22); FR-PURO (Jul 22); FFPR (Nov 22); 99-CHR (Jan 25, 2024); Lin-CHR (Feb 1); FFPR (Mar 5); IT (May 31) | Purolator; Chrome; Actualización de Chrome; 4K Sports |
| AFETZEDE | ALEX-2 (Mar 14, 2024) | İnat TV PRO |
| ANAKONDA | drop1 (Mar 15, 2024); inat1 (Mar 19); 22mart (Mar 23) | İnat TV Video Oynaticisi |
| TONY | Chrome (Mar 23, 2024); Chrome (May 3) | Chrome Güncelleme |
Source: Cleafy appendix and campaign analysis.
How Medusa reached Android phones
Phishing and smishing
Traditional campaigns used deceptive messages and links to persuade a recipient to install an APK. Lures included TV or video players, premium services, refund or government-themed applications, and fake Chrome or Android updates.
Dropper and side-loading chains
In newer campaigns, a dropper downloaded from an untrusted source helped install or load the payload, often while presenting itself as a software update. An update delivered as an APK from a text message, social-media post, pop-up or random website is not the same as an update delivered through Google Play or Android’s normal system-update controls.
Rank #3
- THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
- PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
- SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
- GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
- MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.
Do not assume that every suspicious update package is Medusa, but treat the delivery method as a high-risk warning sign.
What changed in the newer variant
Cleafy described a more compact variant that reduced its visible footprint while retaining functions useful for fraud. The report says 17 commands from an earlier variant were removed and five new commands were observed:
| Command | Reported function |
|---|---|
destroyo |
Uninstall a specified application |
permdrawover |
Request permission to draw over other applications |
setoverlay |
Set a black-screen overlay |
take_scr |
Take a screenshot |
update_sec |
Update the user secret |
The spelling destroyo follows Cleafy’s appendix. The lightweight permission set may make initial review by a user, automated screening system or analyst less conspicuous; it does not make the application safe. The malware can later seek Accessibility or other special access, and a reduced manifest should not be treated as proof that capabilities are absent.
Rank #4
- STAY PROTECTED EVERYWHERE you go, at home, in a café, at the airport—everywhere—on ALL YOUR DEVICES, with cloud-based protection against viruses & other online threats
- Webroot PASSWORD MANAGER by Last Pass creates, encrypts, and saves all your passwords, so you only have to remember one.
- As the #1 TRUSTED PROVIDER OF THREAT INTELLIGENCE, you know you’re in good hands. Stay safe from viruses, ransomware, phishing, and more.
- Webroot SOFTWARE UPDATES ITSELF AUTOMATICALLY, so you always have the most current protection without lifting a finger—and updates happen in the background so they won’t slow you down.
- PREMIUM FEATURES: Encrypts & protects passwords and account information for all your devices so you can stay protected wherever you are.
Secondary reporting describes some samples as requesting combinations of Accessibility Services, broadcast SMS, Internet, foreground-service, package-query and package-deletion permissions. That list is not a universal signature for every Medusa sample. See secondary coverage alongside the primary report.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to assess a suspicious Android app
No single indicator proves infection. Judge the app’s source, purpose, publisher, requested access and behavior together.
- It arrived through an unsolicited SMS, social-media message or pop-up.
- It claims to be a Chrome, Android or security update but is an APK outside the normal update path.
- It imitates a streaming service, delivery company, government or refund service.
- It requests Accessibility access, permission to draw over other apps, notification access or SMS access without a clear reason.
- Its name or icon closely imitates a trusted brand, disappears from the launcher or repeatedly opens a full-screen or black-screen display.
Review special access
Check recent installations and inspect Settings → Accessibility, Settings → Apps and Special app access for unfamiliar entries. Also review overlay, notification, SMS and device-administrator privileges. Samsung, Pixel, Xiaomi and other manufacturers may rename or relocate these controls, so use the Settings search box if necessary. Legitimate apps can use some of these permissions; the app’s purpose and installation source matter.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
- Android Security & protection
- Daily Virus Database checkup and updates
- Scan Apps and Files
- System Cleaner Integrated
- Virtual Private Network (VPN)
What to do if a suspicious app was installed
- Disconnect mobile data and Wi-Fi, or enable airplane mode, while seeking help.
- Contact your bank using the number on its official website or payment card, never a number supplied by the app. Ask for transaction review, session revocation and replacement of exposed payment credentials where appropriate.
- From a clean device, change banking and email credentials and review other accounts that used the phone.
- On the affected phone, revoke Accessibility, overlay, notification and device-administrator access, then uninstall the unfamiliar app.
- If removal is blocked or the app keeps reopening, reboot into Android Safe Mode if supported, revoke its special access and try again.
- Run the phone’s built-in security scan. If suspicious behavior persists or you cannot establish that the compromise is gone, perform a factory reset.
- Before deleting evidence, save the app name, installation source, messages and relevant timestamps if a bank, fraud team or law enforcement may need them.
Uninstalling one app does not guarantee that credentials, sessions or authentication messages were not exposed. SMS-based two-factor authentication can be undermined when criminals control the legitimate banking device, although device compromise does not defeat every form of multi-factor authentication.
What the Cleafy disclosure does—and does not—establish
- It establishes observed campaign activity from July 2023 through the May–June 2024 investigation and identifies five botnets, 24 listed entries and seven target countries.
- It does not provide a complete number of infected people, a total loss estimate or proof that all seven countries experienced equal exposure.
- It does not show that all campaigns were distributed through Google Play.
- It is not, on its own, evidence that these exact campaigns remain active in 2026 or that a simultaneous worldwide outbreak is occurring.
Read the original report, published June 20, 2024, at Cleafy Labs. Cleafy’s related overview is available at Cleafy’s press summary.
The Bottom Line
The practical warning remains current even though the disclosure is from 2024: do not install APK updates delivered through messages or untrusted websites, and treat unexplained Accessibility or overlay requests as high-risk. If a suspicious app reached a phone used for banking, isolate the device and contact the bank from an official channel before attempting cleanup.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




