The Android banking trojan Red Alert was observed targeting more than 60 banking applications across multiple countries, along with at least one social platform, Instagram, by displaying fake login overlays when victims opened selected apps. The malware checked which application was in the foreground and then pulled the appropriate overlay configuration from its command-and-control infrastructure, allowing it to capture usernames, passwords, and other entered data and send them back to attackers.
Researchers reported that Red Alert 2.0 was being distributed through third-party Android app stores while posing as legitimate software such as WhatsApp, Viber, Android updates, and Flash Player updates. Beyond credential theft, the trojan supported SMS interception and sending, changing the default SMS app, collecting contacts and call data, issuing USSD commands, launching apps, requesting admin privileges, and blocking incoming calls from banks to interfere with fraud checks; it was also reportedly advertised on underground forums for $500, raising concerns that more criminals could deploy it against Android devices up to version 6.0.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Trend Micro reported that Red Alert 2.0 was being distributed through third-party app stores while masquerading as apps such as WhatsApp, Viber, Android updates, and Flash Player updates. The report said the malware used overlays to steal credentials, intercepted SMS messages, and blocked incoming bank calls.
ThreatFabric described the Android banking trojan Red Alert, detailing its overlay-based credential theft, command-and-control design, and command set. The report said the malware targeted more than 60 banking apps across multiple countries as well as Instagram.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 19 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.