Categorie: News

RedHook, the Android malware evolves and becomes more dangerous

RedHook, a banking trojan for Android devices identified for the first time in July 2025 by the company Cyble, has returned to strike with a renewed guise and significantly more insidious.

A recent report published on July 9, 2026 by Group-IB reveals that the malicious code is now capable of abusing the wireless debugging tool (ADB) to gain deep access to the system.

This evolution allows attackers to drain victims’ bank accounts operating in a completely stealthy manner.

RedHook, the Android Trojan that drains your bank account evolves

Credits: Canva

Despite the new capabilities, RedHook’s entry strategy remains rooted in social engineering. Cybercriminals impersonate bank employees or government officials, contacting potential victims via calls or messages. The aim is to convince the user to download and install an APK file from fraudulent websites, designed to convincingly imitate the Google Play Store.

Once installed, the malicious application requires the Accessibility permissions. Having obtained this essential consent, the malware acts autonomously: it navigates the device’s Developer Options, enables wireless debugging, and pairs as if it were an authorized computer.

This procedure guarantees the Trojan almost total control over the device, a privilege normally inaccessible to standard applications, without resorting to any complex technical exploits but simply bending a native interface to its purposes.

Code resilience and persistence

Researchers from Group-IB have highlighted that this new iteration is particularly tenacious and hard to eradicate. The Trojan employs several tactics to keep its background execution: it plays silent audio tracks, prevents the processor from entering sleep mode, and uses two twin services programmed to restart each other if the user or the operating system attempts to interrupt one.

The approach of exploiting Accessibility permissions to perform active actions, rather than merely watching the screen and logging keystrokes, aligns this threat with other families of recent malware such as Vultur and Brokewell.

It should be noted that Apple devices are immune to this specific technique, because the iOS operating system does not expose tools comparable to wireless ADB for downloaded applications.

Defense and Prevention

The primary barrier against this type of attack remains the User caution and use of official channels. Because the malware requires manual installation, downloading software exclusively from Google’s official store and keeping the Play Protect protection system active neutralizes the risk from the outset.

It is vital to distrust unsolicited urgent communications, verify the caller’s identity, and categorically refuse granting Accessibility permissions to apps that do not have a clear need, as well as periodically check that wireless debugging has not been enabled without your knowledge.

Meanwhile, Google is developing specific countermeasures. The Mountain View company is working on an update to its Advanced Protection mode which, when fully implemented, should block access to developer options for users who enable it, closing this dangerous backdoor before criminals find new ways to exploit it.

Luca Zaninello

Appassionato del mondo della telefonia da sempre, da oltre un decennio si occupa di provare con mano i prodotti e di raccontare le sue esperienze al pubblico del web. Fotografo amatoriale, ha un occhio di riguardo per i cameraphone più esagerati.

Recent Posts

OpenAI recruits an army of influencers: ChatGPT must become part of the daily routine

OpenAI has launched a major campaign with social creators, not targeting tech reviewers but those…

12 hours ago

RemControl, the Android banking Trojan that also targets Italian bank accounts

A new banking trojan for Android, called RemControl, is targeting users in several countries, including…

13 hours ago

Getting your card close to the DualSense to buy a game? Sony dreams of a controller that acts as a POS

Sony has filed a patent that would transform the PlayStation controller into a small payment…

15 hours ago

Xiaomi 18 Pro and Pro Max now work with Apple Watch

The Xiaomi 18 Pro series becomes compatible with Apple Watch. It's a feature designed for…

15 hours ago

Apple and Qualcomm renew collaboration despite Cupertino seeking independence

Apple and Qualcomm have announced the extension of their global patent licensing agreement, which will…

17 hours ago

Gemini now has a face: Google’s AI speaks and changes expression in real time

Google has introduced Live Avatar, a novelty of Gemini 3.8 Live that pairs the assistant's…

17 hours ago