RedWing is an Android malware-as-a-service operation centered on a commercialized spyware and banking-fraud toolkit distributed through Telegram and delivered via phishing pages that impersonate legitimate mobile app stores. Victims are lured into sideloading malicious APKs and then socially engineered into granting high-risk permissions, particularly Accessibility Service, notification access, default SMS handler status, overlay-related privileges, and battery-optimization exemptions. The malware does not rely on an Android exploit; instead, it abuses legitimate platform features and user-approved permissions to gain deep control over infected devices.
Once installed, RedWing supports extensive credential and financial-data theft. It deploys fraudulent overlays on banking and cryptocurrency applications to capture logins, payment-card data, PINs, and seed phrases, and it intercepts SMS-based one-time codes by reading incoming messages and setting itself as the default SMS application. It can also enable call forwarding to bypass voice-based authentication and fraud-verification calls. Accessibility abuse enables screen reading, simulated user interaction, and theft of sensitive data displayed on screen, while a built-in keylogger captures user input in real time.
RedWing also provides broad surveillance and remote-control functionality. Documented capabilities include live screen streaming via MediaProjection with VNC-style control, remote screen locking, camera activation, microphone recording, file access, theft of contacts and call logs, device-location tracking, and collection of device telemetry. The malware hides its icon after setup and uses obfuscation and dynamic loading of encrypted code to reduce visibility and hinder analysis. Some reporting also attributes proxy-tunneling support and the ability to dynamically update overlay targets and phishing injects from the operator panel without redistributing a new build.
The operation is notable for its mature criminal-service model. Operators reportedly lease RedWing through Telegram using subscription tiers, referral incentives, tutorials, and bot-assisted APK generation and customization, lowering the barrier to entry for less-skilled fraud actors. Targeting has focused heavily on financial institutions, especially Russian banks, with additional interest in cryptocurrency and messaging users. RedWing has been assessed as likely related to or derived from the Oblivion malware family based on similarities in droppers and overlays, but that relationship remains unconfirmed. Claimed links to Russian threat actors have also been reported, though attribution is not confirmed.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
From the panel, attackers drop fake login overlays on top of real banking and crypto apps. These injects capture card numbers, PINs, and seed phrases.
It deploys fake login screens over real banking and crypto apps to steal credentials...
Operators can trigger the camera and microphone, read files, steal contacts and call logs, and track location.
From the panel, attackers drop fake login overlays on top of real banking and crypto apps. These injects capture card numbers, PINs, and seed phrases.
It deploys fake login screens over real banking and crypto apps to steal credentials...
RedWing reports each granted permission to its C2 in real time. That telemetry tells operators which commands will work.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android malware offered as a rental MaaS platform that targets banking, crypto, and messaging users via phishing pages and sideloaded APKs. It uses overlays, Accessibility abuse, SMS interception, call forwarding, VNC screen streaming, keylogging, camera/mic capture, file and contact theft, location tracking, and can pool infected devices into a DDoS botnet.
Android spyware/RAT offered as Malware-as-a-Service via Telegram. It supports data exfiltration (SMS, contacts, call logs, files, photos), real-time screen streaming via VNC, keylogging, banking and crypto overlays, 2FA interception, audio/video capture, DDoS, proxy tunneling, and dynamic encrypted DEX loading for evasion.
Android malware sold as a MaaS offering via Telegram. It uses phishing-linked fake app store pages and custom droppers to trick users into sideloading malicious apps, abuses Accessibility, default SMS handler, and notification permissions, steals banking and crypto credentials via overlays, intercepts SMS 2FA codes, captures PIN/card/CVV data, enables call forwarding, supports remote camera/microphone activation, live screen streaming via VNC, keylogging, file/contact/call-log/location theft, and can also turn infected devices into a DDoS-capable botnet.
Android banking malware sold as a subscription service via Telegram. It uses phishing-delivered droppers, staged permission abuse, Accessibility abuse, SMS interception, overlay attacks, call forwarding, live screen streaming, keylogging, remote device control, camera/microphone access, file/contact/call-log theft, location tracking, and can also use infected devices for denial-of-service activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.