HackMyIP
← Back to News
2026-07-07 The Hacker News

RedWing Android Malware Rented on Telegram Targets Banking Apps

MalwarePhishingThreat Intel

A new Android malware-as-a-service operation dubbed RedWing is being advertised on Telegram as a turnkey bank-fraud kit, enabling low-skill criminals to hijack victim devices, harvest banking credentials, and intercept one-time passcodes protecting financial accounts. Researchers at Zimperium's zLabs identified RedWing as an apparent successor to Oblivion, a $300-per-month rental malware strain documented earlier this year. The kit is sold in subscription tiers with referral discounts, setup guides, and video tutorials, and a Telegram bot auto-generates a customized dropper and payload on demand. A significant share of the resulting samples currently bypass conventional mobile security tools, according to the researchers.

The infection chain begins with a phishing link that leads to a convincing fake app-store page. RedWing's dropper builder can impersonate Google Play, the Samsung Galaxy Store, or Huawei's AppGallery, or create fully custom storefronts complete with fabricated ratings, reviews, and download counts. After coercing the victim into sideloading the app, the malware stages its permission requests one screen at a time. A benign-looking web page renders in the background while sequential pop-ups ask the user to disable battery optimization, register the app as the default SMS handler, enable notifications, and activate Android's Accessibility service, which the malware abuses to read on-screen content and issue UI commands. Users worried about exposure can verify their accounts have not been compromised using an email breach checker and confirm that no banking logins have leaked.

Once Accessibility is granted, RedWing gains near-total control of the device. It overlays fake login screens on top of legitimate banking and cryptocurrency apps, reads incoming SMS messages to capture one-time passcodes, and uses Accessibility hooks to lift card numbers and PINs directly off the display. It can silently forward incoming calls to the attacker using the *21* carrier code, neutralizing phone-based verification and fraud-alert callbacks. Additional capabilities include live screen streaming, keystroke logging, camera and microphone activation, file and contact exfiltration, location tracking, and pooling infected devices to launch denial-of-service attacks against chosen targets. Banking customers can mitigate credential-stuffing risk by running any new login passwords through a password checker to confirm they have not appeared in known dumps.

Targeting is split into two tracks. The apps monitored through Accessibility are hardcoded into each build, meaning a fresh APK is generated each time a buyer selects victims. Overlay targets, by contrast, can be updated remotely from the operator's control panel without redeploying the app. Zimperium counted 82 targeted institutions across multiple sectors, with heavy concentration on Russian financial services, though the panel allows operators to change targets at will. Telemetry from one sample pointed to a cloned RuStore landing page, reinforcing assessments that the campaign is primarily aimed at the Russian market and represents a continued evolution of the Oblivion malware family into a more accessible, industrialized fraud platform.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Auth Check →Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

How phishing attacks work →How to check if an email is safe →SPF, DKIM & DMARC explained →