RedHook: The worrying return of Android spyware targeting your bank accounts

IN BRIEF

  • RedHook turn it awayWireless ADB to obtain a full access to the smartphone (system shell, screenshot, keystrokes, unlocking).
  • Social entry point: link via SMS, call, email or social media leading to a fake store and the installation of a APK.
  • The request foraccessibility permissions This is used to discreetly enable ADB in developer options.
  • Enhanced persistence: use of a WakeLock and screen retention via a nearly invisible pixel to remain active.
  • Resilience: two services in cross resurrection which mutually reinforce each other complicate the removal.
  • Propagation: initial campaigns at Vietnam, activity now detected in Indonesia — risk of geographical expansion.
  • Simple measures: prioritize the Google Play Store, refuse suspicious permits and prevent the installation ofAPK received via links.
  • Possible mitigation method: the mode Advanced protection This could disable access to developer options, but it is not yet widespread.

RedHook reappears in a strengthened form: this Android spyware exploits the Wireless ADB to obtain a full access on the phone and empty the bank accounts of his victims. The trap begins with a social engineering classic — a link received via SMS, call, or message leading to a fake website mimicking the store and the installation of an APK that requests accessibility permissions.

Once installed, the application discreetly activates ADB, opens a shell access with system privileges and captures keystrokes and displays in real time. Its robustness stems from persistence techniques: WakeLock, keeping the screen in place via a single pixel and a mechanism for resurrection based on two mutually reinforcing services. Initially targeting the Vietnamthe threat shows signs of spreading towards Indonesia, hence the recommendation to favor the Google Play Store, to avoid APKs transmitted via links and to remain attentive to permission requests — one mitigation approach involves the mode Advanced protection to limit access to developer options.

RedHook reappears in a more aggressive version: this Trojan horse now exploits theWireless ADB to take almost total control of the phones Android and empty the bank accounts of its victims. By relying on social manipulation techniques, access permissions, and a two-service “resurrection” mechanism, the malware makes its removal particularly difficult. Public analyses and removal guides detail its modus operandi and the initial infection hotspots, primarily in Southeast Asia.

Mode of infection and social engineering

The infection process begins through classic vectors: SMS messages, phone calls, emails, or social media posts containing a malicious link. Attackers impersonate support services or representatives of well-known organizations to gain the target’s trust. The victim is then redirected to a fake website, often mimicking the legitimate one. Google Play Store, which offers the download of a file APKOnce installed, the application requests accessibility permissions presented as essential for operation.

A trap in accessibility permissions

Once granted, these permissions allow the malware to operate covertly: it can read keystrokes, intercept notifications, unlock the screen, and live stream the device’s display. Fake dialogue and social pressure are used to mask the extent of the requested permissions, making the user less suspicious during installation.

The central role of wireless ADB

The major innovation of this version of RedHook depends on the discreet activation of theWireless ADB (Android Debug Bridge) via the developer optionsBy manipulating these settings from the malicious application, the malware gains shell access with system identifier UID 2000, equivalent to deep control of the device.

Consequences of shell access

With this access, the malware can execute low-level commands: intercepting keystrokes, continuously capturing screenshots, remotely managing the display, and automating transactions. The exploitation of a tool designed for developers illustrates how legitimate functionalities can be misused by malicious actors.

A reinforced version that is difficult to neutralize

If an iteration of RedHook Although it had already been documented the previous year, the current variant proves to be more resistant. To remain active, it uses a WakeLock and a display trick: a single pixel keeps the screen “on” invisibly, making the system believe that an essential process is taking place.

Cross resurrection mechanism

Two separate services operate in parallel and monitor each other: if one is stopped, the other restarts it immediately. This mechanism of resurrection cross-referencing significantly complicates manual removal, even for a knowledgeable user attempting to stop processes via the application manager.

Areas affected and geographical evolution

The initial campaigns heavily targeted Vietnam. Researchers have since observed an expansion into Indonesia, indicating ongoing spread in Southeast Asia. At this stage, no significant spread to Europe has been confirmed, but the history of malware shows that a proven modus operandi can quickly be exported to other markets.

Safety recommendations and mitigation strategies

Faced with this threat, a few simple steps remain essential: only install applications from the Google Play Storerefuse any unjustified access permission requests and avoid opening the files APK received via external link. Practical resources explain how to identify and uninstall RedHook and other similar threats — see in particular the removal guides offered by BugsFighter and PCRisk for step-by-step procedures.

Measures proposed by publishers

Google is exploring ways to block the abusive activation of developer options The “Advanced Protection” mode could eventually restrict access to these settings and limit the ability of malware to activate the…Wireless ADBThis feature is not yet deployed on a large scale, and in the meantime, user vigilance remains the best defense.

Additional sources and analyses

The first reports and technical analyses of this variant are documented by cybersecurity teams and specialized media outlets. For a detailed reading of the initial analysis and context, consult the study published by Cyble. Summaries and alerts in French are available from 01net and PhonAndroid, which explain how the malware works and the risks to bank accounts.

For practical removal guides and step-by-step advice: BugsFighter And PCRisk offer tailored procedures. The original comparative analysis is available on the Cyble blog: cyble.comAdditional media coverage can be found on 01net And PhonAndroid.

FAQ — RedHook: The worrying return of Android spyware targeting your bank accounts

Q: What is the RedHook Trojan horse ?

A: RedHook is a spyware for Android, which hijacks legitimate system functions to obtain a full phone access and compromise the victim’s bank accounts.

Q: How does RedHook manage to install itself on a device?

A: The infection often begins with a message (text message, call, email, or social media message) containing a link to a fake website resembling the Google Play StoreThe victim installs an APK file and accepts requests foraccessibility permissionpresented as necessary for the proper functioning of the application.

Q: What role does theWireless ADB in the attack?

A: After installation, RedHook discreetly activates theWireless ADB (Android Debug Bridge) by manipulating developer options. This allows him to obtain a shell access with the system identifier UID 2000, offering almost total rights over the device.

Q: What can the attacker do once access is gained?

A: With this access, the software can read keystrokes, unlock the screen, And broadcast live the phone’s display. These capabilities facilitate the theft of banking credentials and the takeover of accounts.

Q: Why is RedHook difficult to remove?

A: The recent version uses a WakeLock to remain active and an invisible “single pixel” that keeps the screen on. In addition, two services monitor each other and automatically restart if one stops: this is called cross resurrection mechanismwhich greatly complicates manual neutralization.

Q: How to recognize a RedHook infection?

A: Possible signs: suspicious requests foraccessibility permission, installing an APK outside of the Google Play Storeabnormal network activity, battery draining slowly despite the screen appearing to be off, or inability to disable certain applications/services.

Q: Where was RedHook observed?

A: The first campaigns targeted the VietnamRecent analyses show an extension towards IndonesiaNo confirmed spread in Europe so far, but the risk of export exists.

Q: What precautions should be taken to protect oneself?

A: Key recommendations: only install applications from the Google Play Store, refuse requests foraccessibility permission unjustified, never install APKs received via an external link, and beware of solicitations pretending to be technical support.

Q: Can Google fix the vulnerability exploited by RedHook?

A: Google is considering options, including through the mode Advanced protection which could disable access to developer options, thus closing the door used to enable theWireless ADBHowever, this solution is not yet officially deployed on Android.

Q: What should you do if you think you are infected?

A: Recommended actions: disconnect network access, avoid entering sensitive information, contact the bank immediately to report a risk of fraud, and consult a mobile security specialist to attempt complete removal, as simply closing an application may not be sufficient due to the resurrection mechanism.

Previous

Leave a Comment