RedHook, a banking trojan for Android devices identified for the first time in July 2025 by the company Cyble, has returned to strike with a renewed guise and significantly more insidious.
A recent report published on July 9, 2026 by Group-IB reveals that the malicious code is now capable of abusing the wireless debugging tool (ADB) to gain deep access to the system.
This evolution allows attackers to drain victims’ bank accounts operating in a completely stealthy manner.
RedHook, the Android Trojan that drains your bank account evolves

Despite the new capabilities, RedHook’s entry strategy remains rooted in social engineering. Cybercriminals impersonate bank employees or government officials, contacting potential victims via calls or messages. The aim is to convince the user to download and install an APK file from fraudulent websites, designed to convincingly imitate the Google Play Store.
Once installed, the malicious application requires the Accessibility permissions. Having obtained this essential consent, the malware acts autonomously: it navigates the device’s Developer Options, enables wireless debugging, and pairs as if it were an authorized computer.
This procedure guarantees the Trojan almost total control over the device, a privilege normally inaccessible to standard applications, without resorting to any complex technical exploits but simply bending a native interface to its purposes.
Code resilience and persistence
Researchers from Group-IB have highlighted that this new iteration is particularly tenacious and hard to eradicate. The Trojan employs several tactics to keep its background execution: it plays silent audio tracks, prevents the processor from entering sleep mode, and uses two twin services programmed to restart each other if the user or the operating system attempts to interrupt one.
The approach of exploiting Accessibility permissions to perform active actions, rather than merely watching the screen and logging keystrokes, aligns this threat with other families of recent malware such as Vultur and Brokewell.
It should be noted that Apple devices are immune to this specific technique, because the iOS operating system does not expose tools comparable to wireless ADB for downloaded applications.
Defense and Prevention
The primary barrier against this type of attack remains the User caution and use of official channels. Because the malware requires manual installation, downloading software exclusively from Google’s official store and keeping the Play Protect protection system active neutralizes the risk from the outset.
It is vital to distrust unsolicited urgent communications, verify the caller’s identity, and categorically refuse granting Accessibility permissions to apps that do not have a clear need, as well as periodically check that wireless debugging has not been enabled without your knowledge.
Meanwhile, Google is developing specific countermeasures. The Mountain View company is working on an update to its Advanced Protection mode which, when fully implemented, should block access to developer options for users who enable it, closing this dangerous backdoor before criminals find new ways to exploit it.



