Researchers reported RedWing, a newly identified Android spyware and malware-as-a-service operation marketed through Telegram and distributed via sideloaded apps and mobile phishing pages. The service packages custom droppers, fake app-store lures, phishing templates, operator guides, and subscription tiers that lower the barrier for bank-fraud actors. Investigators said the campaign heavily targets financial institutions—especially Russian banks and crypto services—and currently includes targeting for 82 institutions across multiple sectors, with infrastructure and tradecraft suggesting a strong Russian-market orientation.
Once installed and granted permissions, RedWing gives operators extensive control over infected devices by abusing Android Accessibility Services, overlay permissions, default SMS handler privileges, and MediaProjection. The malware can harvest credentials and one-time codes, intercept SMS, enable call forwarding, stream the screen, log keystrokes, capture audio and camera feeds, and access files, contacts, call logs, and location, allowing it to bypass SMS- and voice-based 2FA. Researchers also found similarities to the Oblivion malware family and said RedWing can dynamically update targeted apps and phishing overlays from its command-and-control panel without requiring a new malware build.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
Zimperium zLabs reported RedWing as a newly identified Android spyware and malware-as-a-service operation distributed via Telegram and mobile phishing sites. The report described a mature commercial toolkit targeting financial institutions, especially Russian banks and crypto services, and noted similarities to the Oblivion malware family.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourceinfosecurity-magazine.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcezimperium.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.