RedWing is an Android malware-as-a-service operation centered on a commercialized mobile spyware and banking-fraud toolkit. It is marketed through Telegram with subscription tiers, operator documentation, tutorial material, referral incentives, and bot-assisted generation and obfuscation of customized malicious APKs, lowering the barrier to entry for fraud operators. RedWing is distributed through phishing infrastructure that impersonates legitimate mobile app stores and relies on sideloading and user-approved permissions rather than exploitation of an Android vulnerability.
Once installed, RedWing uses staged social engineering to obtain high-risk Android privileges including Accessibility access, SMS-related privileges, notification access, overlay capability, and battery-optimization exemptions. It can hide its icon and continue operating in the background. The malware is designed primarily for banking and cryptocurrency fraud, using overlay attacks against targeted applications to steal credentials and other sensitive financial data. It also intercepts SMS messages and one-time passcodes, and can enable call forwarding to bypass voice-based verification and fraud-confirmation calls.
RedWing provides extensive surveillance and remote-control functionality. Reported capabilities include VNC-style live screen streaming, keylogging, camera and microphone activation, collection of contacts, call logs, files, photos, and location data, and broader device manipulation through Accessibility abuse. Infected devices can also be conscripted into denial-of-service activity. Targeting has been reported against dozens of institutions, with a strong emphasis on Russian financial organizations and related services.
RedWing has been assessed as likely related to, or evolved from, the Oblivion Android malware family based on similarities in droppers and overlay mechanisms, though that lineage is not definitively confirmed. Reporting has also noted possible links to Russian threat actors, but attribution remains unconfirmed.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
RedWing's core trick was credential harvesting through fake overlays. When a victim opened a targeted banking or cryptocurrency app, it dropped a convincing login screen on top to steal their details...
It also provided live VNC screen control, keylogging and covert recording from the camera and microphone.
It deploys fake login screens over real banking and crypto apps to steal credentials...
Operators can trigger the camera and microphone, read files, steal contacts and call logs, and track location.
RedWing's core trick was credential harvesting through fake overlays. When a victim opened a targeted banking or cryptocurrency app, it dropped a convincing login screen on top to steal their details...
It also provided live VNC screen control, keylogging and covert recording from the camera and microphone.
It deploys fake login screens over real banking and crypto apps to steal credentials...
RedWing reports each granted permission to its C2 in real time. That telemetry tells operators which commands will work.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android malware offered as a rental MaaS platform that targets banking, crypto, and messaging users via phishing pages and sideloaded APKs. It uses overlays, Accessibility abuse, SMS interception, call forwarding, VNC screen streaming, keylogging, camera/mic capture, file and contact theft, location tracking, and can pool infected devices into a DDoS botnet.
Android spyware/RAT offered as Malware-as-a-Service via Telegram. It supports data exfiltration (SMS, contacts, call logs, files, photos), real-time screen streaming via VNC, keylogging, banking and crypto overlays, 2FA interception, audio/video capture, DDoS, proxy tunneling, and dynamic encrypted DEX loading for evasion.
Android malware rented via Telegram as a malware-as-a-service offering. It builds malicious APKs for customers, uses fake app-store pages for distribution, abuses accessibility and SMS permissions, steals banking and crypto credentials via overlays, intercepts SMS for 2FA bypass, forwards calls, enables VNC control, keylogging, camera/microphone recording, and can conscript devices into DDoS botnets.
Android malware sold as a MaaS offering via Telegram. It uses phishing-linked fake app store pages and custom droppers to trick users into sideloading malicious apps, abuses Accessibility, default SMS handler, and notification permissions, steals banking and crypto credentials via overlays, intercepts SMS 2FA codes, captures PIN/card/CVV data, enables call forwarding, supports remote camera/microphone activation, live screen streaming via VNC, keylogging, file/contact/call-log/location theft, and can also turn infected devices into a DDoS-capable botnet.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.