Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Other mechanisms include a five-minute watchdog alarm, automatic restart after device boot, and setting oom_score_adj to -1000 to reduce the likelihood of being killed when available system memory is low.
Next, the malware deploys a Shizuku-based framework to execute shell commands, grant itself additional permissions, modify protected Android settings, silently install or remove applications, and perform various operations without displaying user dialogs.
The malicious app is spread through social engineering, with attackers posing as government officials or bank support staff over phone calls and messaging apps like Zalo.
Victims are guided to fake websites styled to resemble the Google Play Store, where they are tricked into downloading a malicious APK.
RedHook implements a two-service cross-process resurrection mechanism for persistence. Each service runs in a separate process and binds to the other via bindService() with BIND_AUTO_CREATE flag... creating a loop that requires both processes to be terminated simultaneously to break.
Other mechanisms include a five-minute watchdog alarm, automatic restart after device boot, and setting oom_score_adj to -1000 to reduce the likelihood of being killed when available system memory is low.
RedHook flips this developer feature into an attack tool by running automated taps through the Accessibility service, turning on Developer Options, enabling Wireless Debugging, and pairing itself as though it were an authorized computer.
It also grants WRITE_SECURE_SETTINGS. With that, it is able to modify entries in Settings.Secure.
Other mechanisms include a five-minute watchdog alarm, automatic restart after device boot, and setting oom_score_adj to -1000 to reduce the likelihood of being killed when available system memory is low.
After that, the malware retrieves the pairing code displayed on the screen and connects to the phone’s ADB service via the loopback interface (127.0.0.1). Once paired, the malware gains shell (UID 2000) privileges, which are significantly more powerful than those available to normal Android apps, though not root-level.
RedHook flips this developer feature into an attack tool by running automated taps through the Accessibility service, turning on Developer Options, enabling Wireless Debugging, and pairing itself as though it were an authorized computer.
The entire attack chain does not require the device to be rooted, so it works across all Android devices as long as the user is tricked into approving the Accessibility Service permission request.
The latest version of RedHook is distributed through social engineering, via messages and phone calls where attackers impersonate government agencies or financial institutions to direct victims to fake Google Play sites.
RedHook flips this developer feature into an attack tool by running automated taps through the Accessibility service, turning on Developer Options, enabling Wireless Debugging, and pairing itself as though it were an authorized computer.
RedHook executes Shizuku code as part of its attack chain, using it as a privileged server (libmx.so) to invoke privileged Android APIs as UID 2000.
RedHook flips this developer feature into an attack tool by running automated taps through the Accessibility service... all while a hidden overlay screen keeps the victim in the dark.
RedHook implements a two-service cross-process resurrection mechanism for persistence. Each service runs in a separate process and binds to the other via bindService() with BIND_AUTO_CREATE flag... creating a loop that requires both processes to be terminated simultaneously to break.
At the same time, the malware retains its remote access trojan (RAT) features, allowing it to stream the screen, intercept keystrokes, automate UI interactions, and steal credentials.
At the same time, the malware retains its remote access trojan (RAT) features, allowing it to stream the screen, intercept keystrokes, automate UI interactions, and steal credentials.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another Android malware that implemented a similar Wireless ADB abuse mechanism.
Referenced for comparison as a RAT noted for persistence through paired services that restart each other.
Android remote access trojan distributed through social engineering via phone calls and messaging apps, redirecting victims to fake Google Play or government/financial portals. It abuses Accessibility Service to enable wireless ADB debugging, uses an embedded ADB client and Shizuku to gain privileged access, supports silent app install/uninstall, settings modification, permission grants, low-level input capture, screen streaming, persistence, and C2 over WebSocket/RTMP/REST.
Android remote access trojan that abuses Wireless ADB and Accessibility permissions to gain shell-level privileges on-device, then uses a Shizuku-based framework to execute privileged commands, stream the screen, intercept keystrokes, automate UI actions, steal credentials, collect contacts and SMS, manage apps, create overlays, activate the camera, and maintain persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.