Oblivion is an Android remote access trojan sold as a commercial subscription-based malware offering. It has been marketed as an easy-to-use rent-a-malware kit that lowers the barrier to entry for cybercriminals and stalkerware-style operators, with public-facing sales and tooling for generating trojanized Android applications. Oblivion is associated with fake update lures, particularly prompts impersonating Google Play or Google services updates, and relies on social engineering rather than a disclosed Android exploit to gain installation and permissions.
Once installed, Oblivion abuses Android Accessibility Service to obtain broad control over the device and silently grant or facilitate additional permissions. Reported capabilities include theft of SMS messages, including banking one-time codes, keylogging to capture passwords and PINs, covert remote control, and live screen viewing. It can reportedly mask attacker activity by displaying a fake system update animation while the operator interacts with the device in the background, and it has been described as capable of remotely unlocking a phone after reboot. The malware is designed for broad Android compatibility and has been advertised as bypassing OEM security layers across multiple major Android distributions.
Oblivion has been described as part of the Android malware-as-a-service ecosystem and as a precursor or likely ancestor of RedWing, an Android spyware operation that shares similarities in droppers and overlay mechanisms. Reporting has noted possible links between the broader activity around RedWing and Russian threat actors, but any direct attribution for Oblivion itself remains unconfirmed. Oblivion is primarily relevant to Android users exposed to sideloaded applications and fake update workflows, and its functionality makes it suitable for credential theft, surveillance, and post-compromise remote device control.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Earlier suspected related Android rent-a-malware kit that RedWing may be a variant of, based on shared droppers and overlays.
Referenced as the likely predecessor or closely related malware family to RedWing, based on similarities in the dropper and overlay mechanisms.
Referenced as the apparent malware family root or lineage for RedWing.
Rent-a-malware Android tool described as the apparent predecessor or variant family related to RedWing.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.