The RedHook Android banking trojan has resurfaced with upgraded remote-access capabilities that abuse Android Wireless Debugging and Accessibility features to gain shell-level privileges without rooting the device or exploiting a kernel flaw. Group-IB reported that the malware is being spread through social-engineering lures in which attackers impersonate government officials or bank support staff and direct victims to fake Google Play-style, government, or financial websites hosting malicious APKs, including on services such as AWS S3 and GitHub. Recent activity shows the campaign expanding beyond Vietnam into Indonesia.
After installation, RedHook tricks victims into enabling Accessibility Service, then automates Developer Options and Wireless Debugging, pairs itself over the loopback interface, and launches a privileged helper process running as uid 2000, reportedly using code derived from the Shizuku framework. In this mode, the malware can silently install apps, change secure settings, capture touch input, steal data, and stream screens or video, including screen capture that bypasses the normal MediaProjection consent prompt. Researchers said RedHook maintains persistence through watchdog services, cross-process resurrection, periodic alarms, reboot persistence, wake locks, silent audio playback, and a one-pixel activity, while its WebSocket-based command-and-control infrastructure supports 53 commands.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
Group-IB published analysis that RedHook had re-emerged with new capabilities, including abuse of Android Wireless Debugging and Accessibility features to gain shell-level privileges without rooting devices. The report also described expanded targeting beyond Vietnam into Indonesia, social-engineering delivery via fake government and financial sites, and WebSocket-based command-and-control.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcebleepingcomputer.com
Open sourcecybersecuritynews.com
Open sourcegroup-ib.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.