Fishing hook piercing a cracked smartphone screen showing a mobile banking checking account balance

RedHook Android Trojan Resurfaces with Root-Level Upgrade

A resurfaced Android banking trojan now hijacks a legitimate developer tool to grant itself system-level access without tricking users into rooting their phones.

An Android remote access trojan first identified targeting Vietnamese banking customers in July 2025 has resurfaced with a technique researchers say they have not seen used maliciously before. It abuses a phone’s own wireless debugging feature to seize system-level privileges without the victim rooting the device.

Group-IB researchers Sharmine Low and Ha Thi Thu Nguyen detailed the malware, tracked as RedHook, in a Thursday report. The trojan was originally documented by Cyble researchers in July 2025 as a Vietnam-focused banking threat. Group-IB’s analysis shows it has since expanded into Indonesia and gained new capabilities.

The updated version automates Android’s ADB Wireless Debugging feature, a tool built for developers to control a device over a network rather than a USB cable, to grant itself shell-level privileges under Android’s “uid 2000” system account. It does this by embedding code modeled on Shizuku, a legitimate open-source app that developers use to run privileged commands without rooting a phone. Once activated, RedHook can silently install and remove apps, alter secure settings and grant itself further permissions without triggering the confirmation dialogs Android normally requires.

RedHook is not distributed through Google Play. Infection starts with social engineering: attackers contact victims by phone or messaging apps, impersonating government officials or bank support staff, and direct them to fake websites spoofing government and financial institution branding under the pretext of a required step to access a service. Victims are talked into sideloading an APK from that fake site, meaning they must first enable installs from outside the Play Store on their device.

The APK files themselves are hosted on legitimate cloud platforms, including GitHub repositories and Amazon S3 buckets, which Group-IB said likely helps the download links evade reputation-based blocking.

Once installed, the malware abuses Android’s Accessibility service to walk through the steps needed to enable Wireless Debugging on its own, then uses that access to stream the victim’s screen, log keystrokes, harvest SMS messages and steal lock-screen credentials.

Group-IB counted 53 distinct server-issued commands in the current build, along with a persistence system that uses fake foreground activity, silent audio playback and a five-minute watchdog alarm to survive reboots and prevent the operating system from killing its processes.

“RedHook’s abuse of ADB Wireless Debugging and Shizuku shows how readily attackers can repurpose legitimate tools and open-source frameworks to expand their malware capabilities,” Low and Nguyen wrote. “There is no exploit here, ‘merely’ turning a debugging interface into a path to shell-level privileges.”

Group-IB said no working exploit or vulnerability was involved. The technique repurposes a legitimate debugging interface rather than exploiting a flaw. Users are advised to install apps only from official stores and to treat any Accessibility Service permission request with heightened suspicion.

Number of installation packages for mobile banking Trojans detected by Kaspersky, Q1 2025 — Q1 2026 

RedHook’s growth comes amid a broader spike in mobile banking malware. Kaspersky’s Q1 2026 mobile threat data shows banking trojan installation packages rose roughly 50% quarter over quarter, and for the first time. The Trojan-Banker category became the single largest slice of all detected mobile malware, accounting for nearly 53% of malicious Android packages found in the quarter.

Total
0
Shares
Previous Article
Wiz's GhostApproval and the AI Now Institute's Friendly Fire, defeat the approval prompt and model judgment test.

Cracks in Claude Code, Cursor, Amazon Q, Codex Expose 'Trust Boundaries'

Next Article
Grid of eight identical toy astronaut figures shot in x-ray style, with one figure highlighted in red among the uniform white grid

AI Crawlers Surge on Bank Websites, Radware Data Shows

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading