A newly identified version of the RedHook malware is targeting Android users by misusing a built-in developer feature to gain deep access to phones, according to cybersecurity firm Group-IB. The company says the malware can be used to steal passwords, capture banking information and take broad remote control of infected devices.
How the malware gets in
Group-IB says the new RedHook variant abuses Android’s Wireless Debugging feature, a tool intended for developers. By turning that feature against the victim, attackers are reportedly able to reach shell-level access on the device without requiring a computer or special permissions.
The campaign is currently aimed at users in Vietnam and Indonesia, the firm says. Victims are allegedly contacted through phone calls and messages that pretend to come from banks or government agencies. They are then sent to counterfeit websites designed to resemble the Google Play Store, where they are persuaded to download malicious apps.
Those apps are said to be hosted on GitHub and Amazon cloud infrastructure, helping the operation appear more legitimate and making the payload easier to distribute.
Permissions and device takeover
After installation, the malware reportedly displays deceptive screens that pressure or trick users into granting Accessibility permissions. Group-IB says RedHook then enables hidden developer settings in the background and connects the phone to itself.
That process gives attackers high-level access over the device. In Group-IB’s description, the malware can steal passwords, stream the victim’s screen, capture lock-screen codes and generate fake prompts or dialogs intended to collect banking credentials and other sensitive information.
The use of Android Debug Bridge wireless functionality is central to the attack. According to the firm, this technique allows the operators to obtain shell-level privileges, significantly expanding what they can do on an infected phone compared with more conventional Android malware.
Built to resist removal
Group-IB says the updated RedHook strain also includes several persistence mechanisms designed to make it difficult to remove. Among them are a nearly invisible one-pixel screen activity, silent audio playback and multiple services that can restart one another if one is stopped.
The malware is also said to be able to restore full access after a phone reboot. Taken together, those features make the threat harder to detect and harder to clean from a compromised device, the report says.
Why researchers are watching it
The significance of the new variant, according to Group-IB, lies in its use of legitimate Android developer functionality to bypass the usual limits placed on apps. Rather than relying only on standard malicious app permissions, the operators appear to be using built-in system tools to expand control after installation.
That approach, combined with social-engineering tactics involving fake bank or government outreach and spoofed Google Play pages, suggests a campaign focused on harvesting financial and other sensitive data from mobile users in the targeted countries.
The report describes RedHook as an upgraded and more resilient version of Android malware, with capabilities that go beyond simple credential theft and extend to persistent remote control of the device.
Source: dailyhodl.com