
Group-IB warns of RedHook malware that abuses Android Wireless Debugging to steal passwords and banking info, targeting users in Vietnam and Indonesia.
Group-IB uncovered a new version of the RedHook malware that is hijacking Android phones by abusing the Wireless Debugging feature normally used by developers. The attackers target users in Vietnam and Indonesia with phone calls and messages impersonating banks or government agencies. They direct victims to fake Google Play Store pages hosted on GitHub and Amazon cloud servers.
Once downloaded, the app asks for Accessibility permissions through a fake screen. In the background, the malware turns on hidden developer settings and connects the phone to itself without a cable. "RedHook abuses ADB Wireless Debugging to obtain shell-level privileges," Group-IB said in its report. "With this access, attackers can steal passwords, stream the screen, capture lock screen codes, and create fake dialogs to steal banking information."
The malware uses several tricks to survive removal. It runs a nearly invisible one-pixel screen activity, plays silent audio to keep the process alive, and launches services that restart each other if stopped. After a reboot, it can restore full access. Group-IB said these techniques make RedHook harder to detect than typical Android malware.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.