LIVE · cybersecurity feed
Live wire
android malwarehigh

Telegram-Hosted RedWing Malware Lets Anyone Rent Android Spyware Tools

A new Android spyware operation called RedWing, linked to Russian threat actors, is being offered as a subscription service on Telegram. This Malware-as-a-Service (MaaS) product requires no coding skills and allows attackers to rent tools for stealing credentials, intercepting SMS messages, recording audio and video, and even launching DDoS attacks. RedWing relies on social engineering and user-granted permissions rather than exploiting device vulnerabilities.

zeroday.news · 24d ago

Researchers have discovered RedWing, an Android spyware operation being sold as a subscription service via Telegram, with suspected ties to Russian threat actors. This sophisticated Malware-as-a-Service (MaaS) product lowers the barrier to entry for novice attackers, providing documentation, tutorial videos, and a bot that customizes and builds malicious applications on demand. The entire process, from app customization to building, can be managed through Telegram.

Infection typically begins with a phishing link that directs users to a fake app store page, designed to mimic legitimate stores like Google Play, Samsung Galaxy Store, or Huawei's AppGallery, complete with fake ratings and reviews. Once installed, the malware guides the user through a series of permission requests, including disabling battery optimization for persistent background operation, setting itself as the default SMS handler to intercept two-factor authentication codes, and gaining access to notifications.

With these permissions, RedWing gains extensive control over the device. It can display fake login screens over legitimate banking and cryptocurrency applications to steal credentials. Furthermore, it leverages Android's Accessibility Service to capture PINs, card numbers, and CVV values directly from the screen as they appear. The malware can also silently enable call forwarding using a hidden carrier code, redirecting all incoming calls to an attacker-controlled number, thereby disabling phone-based two-factor authentication and fraud prevention calls.

The spyware's surveillance capabilities extend to remotely activating the device's camera and microphone. Attackers can send commands to capture images or record ambient audio for configurable durations, managed entirely from the remote server. Additional features include live screen streaming via VNC, a real-time keylogger, access to all files on the device, contact lists, call logs, and location tracking.

RedWing's architecture suggests that specific target lists for overlays can be updated remotely, while the applications it monitors through Accessibility are compiled into each custom APK. Researchers identified 82 targeted institutions, with a notable focus on Russian financial firms. The operation does not exploit any Android vulnerabilities, relying instead on users installing apps from unofficial sources and granting excessive permissions.

Beyond espionage and data theft, RedWing can transform compromised Android devices into a botnet capable of launching coordinated Distributed Denial of Service (DDoS) attacks. Attackers can command multiple infected phones simultaneously to flood target websites or servers with traffic, disrupting their availability.

Given that operators can easily reskin the app and change its targets, focusing on the app's name is less effective than observing its behavior. The rise of MaaS operations like RedWing highlights the ease with which attackers can weaponize legitimate Android components for full device compromise through social engineering and the abuse of critical system permissions.

android malwarespywaremalware-as-a-servicetelegramphishing
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.