Red Alert 2.0 is an Android banking trojan that masquerades as legitimate mobile applications and fake software updates to trick users into installing it, primarily through third-party app stores. It has been observed posing as popular messaging applications, media players, VPN tools, Android updates, and Flash Player updates. In some infection chains, an initial lure application retrieves an additional payload after installation, requests elevated device privileges, and can persist even if the original lure app is removed.
The malware is designed to facilitate banking fraud and credential theft on Android devices. It monitors running applications and receives targeting information from command-and-control infrastructure so it can present malicious overlays when selected apps are opened. These overlays imitate legitimate login screens and are used to capture banking credentials and other sensitive account information, which are then exfiltrated to the operators.
Red Alert 2.0 also collects device data including SMS messages, call logs, contact lists, and information about running or targeted applications. It can send SMS messages and has been reported to interfere with victim communications, including blocking incoming calls from banks, likely to hinder fraud-verification attempts and extend the attackers’ window of operation. Command-and-control communications have been observed over HTTP. The malware has been associated with underground commercial distribution, lowering the barrier for financially motivated actors to deploy Android banking malware against mobile users.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The credentials are sent to the attacker’s command-and-control (C&C) server.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan that uses fake apps and update prompts to deliver an additional payload, steals credentials through on-screen phishing overlays, intercepts SMS messages, blocks incoming bank calls, gathers device information, and communicates with a C2 server for targeting instructions.
Android banking trojan that disguises itself as legitimate media, social media, and VPN apps.
Android trojan that uses malicious overlays to steal banking credentials.
Android trojan that can identify the currently running application.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.