Red Alert is an Android banking trojan that uses overlay-based phishing to steal credentials from mobile banking applications and other selected apps. It monitors the foreground application on infected devices and, when a targeted app is opened, displays a fraudulent overlay designed to mimic the legitimate login interface. Victims are shown an error page after submitting data, while the entered credentials are transmitted to attacker-controlled infrastructure. Red Alert has been associated with the Android banking malware ecosystem that expanded significantly in the late 2010s and was noted alongside families such as Cerberus, Exobot, BankBot, GM Bot, and Mazar Bot. It was also part of the period in which several Android banking trojans were commonly operated under a malware-as-a-service model.
The malware targets a broad set of financial institutions across multiple countries, including banks in Australia, Turkey, India, the United States, Ireland, Germany, Spain, France, Italy, and Poland. Its targeting also extends beyond banking to at least some non-banking applications, including social media, indicating a broader credential-harvesting role. Red Alert keeps its overlay target list on the command-and-control side rather than embedding the full list locally, complicating static recovery of its targeting set. To support overlay triggering, it periodically checks which application is currently in the foreground; on newer Android versions it uses Android toolbox-based methods for this purpose.
Red Alert also supports a wider command set beyond credential theft. Documented functions include intercepting SMS messages, sending SMS, changing the default SMS application, collecting SMS, call-log, and contact data, requesting administrator privileges, launching applications, blocking actions, issuing notifications, and sending USSD commands. These features make it suitable for theft of banking credentials and transaction authentication data, as well as broader post-compromise device control. The malware is therefore best characterized as an Android banking trojan focused on overlay phishing, SMS interception, and mobile account takeover.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Delivered malware included ZLoader (a.k.a. Terdot), Gootkit, Ursnif, Corebot, Panda Banker, Atmos, Mazar Bot, and Red Alert Android malware.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Upon opening an application that is targeted by Red Alert an overlay is shown to the user. When the user tries to log in he is greeted with an error page. The credentials themselves are then sent to the C2 server.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan family mentioned as an example of earlier MaaS-based operations in the Android banking malware ecosystem.
Delivered malware included ZLoader (a.k.a. Terdot), Gootkit, Ursnif, Corebot, Panda Banker, Atmos, Mazar Bot, and Red Alert Android malware.
Mentioned as another active Android banking trojan in the ecosystem comparison.
Mentioned only as a comparison point for more sophisticated Android banking malware overlays.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.