HomeSecurityRedWing: New malware service for Android

RedWing: New malware service for Android

A new Android malware, dubbed RedWing, is being marketed on Telegram as a ready-made banking fraud service. It allows even low-skilled criminals to take phone a victim's, steal their banking login details , and record the one-time passwords that protect their accounts.

Article Image: RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service

Zimperium 's zLabs , which discovered the operation, says it looks like a new variant of Oblivion , a tool that rents for $300 a month and was documented earlier this year.

RedWing is sold as a complete product, with subscription plans that include discounts, guides, and how-to videos, meaning the buyer doesn’t need malware-writing. A Telegram bot creates a custom app.

Researchers report that a significant number of the produced droppers and payloads evade conventional security tools.

RedWing: How does infection start?

The infection begins with a phishing link that opens a fake app store. The kit’s dropper builder can mimic Google Play, Galaxy Store, and AppGallery , or create completely custom pages, with fake ratings, reviews, and download counts. The page then convinces the user to install the app outside the official store and authorize its permissions.

See also: CrystalRAT: New MaaS service advertised via Telegram

The app gradually requests its permissions, one screen at a time. A seemingly innocuous website remains in the background while pop-up cards request permissions that appear to be routine: disabling battery restrictions, setting the app as the default text message handler, and enabling notifications.

It also requests the activation of Accessibility service , which the malware exploits to read the screen and control the phone.

RedWing: New malware service for Android

With these permissions, RedWing gains extensive control over the phone. Its capabilities include:

– Fake login screens, called overlays, which appear on top of real banking and cryptocurrency apps to steal passwords.

– Read incoming messages for one-time codes and use Accessibility to capture codes, card numbers, and PINs as they appear on the screen.

– Silently redirecting the victim's incoming calls to the attacker using a hidden carrier code (*21*) to activate call forwarding, which undermines phone verification and bank fraud screening calls.

– Live screen streaming and keystroke recording, allowing operators to monitor and control the phone in real time.

– Enabling the camera and microphone, reading files, stealing contacts and call logs, and tracking location.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

– Gathering infected phones to flood a target with traffic, performing a denial-of-service attack.

See also: SecuriDropper: New DaaS service installs malware on Android

Buyers choose their own targets, and the malware splits its targeting into two. The apps it tracks via Accessibility are embedded in each copy, indicating that a new app is custom-built once a buyer selects targets. Overlay targets, however, can be modified later from the dashboard without having to push a new app.

Article image: Google Search lets creators know more about their reach

Zimperium identified 82 targeted institutions across a variety of sectors, with a strong focus on Russian financial institutions, although this list is subject to change at any time. The evidence suggests a connection to the Russian market: one sample used a fake page for Russia’s RuStore. Experts believe the business is linked to Russian threat actors, but have not confirmed this.

See also: GhostSocks MaaS: Converting compromised devices into proxies

Targeting Android Devices and Protection

Researchers had flagged a nearly identical rental kit for the Russian market, Fantasy Hub, last year. The same techniques appear in Albiriox, which targeted over 400 finance apps, and Klopatra, which used hidden remote control and fake overlays to empty accounts while victims slept.

RedWing does not require an Android exploit. It only works when a user installs the app from outside an official store and approves the permissions, making the installation process the first line of defense.

– Only install apps from official stores and consider any “update” that arrives via link or text message as suspicious.

– Do not enable “installation from unknown sources” and do not grant Accessibility or default text messaging permissions.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS