Malware · 68 days ago
RedWing turns Android fraud into a rented service that can change shape for each buyer, so app-name and hash blocking miss the point. Once installed, the phone becomes a tool for stealing banking logins, one-time codes, and call traffic used to bypass phone-based verification.
Zimperium says the service is sold through Telegram with custom droppers built on demand. The fake app-store pages mimic major storefronts, then push a staged set of permission prompts that end with Accessibility access, screen reading, call forwarding, overlays, and live control.
The risk is not one bad sample. It is a reskinnable Android kit that keeps producing new lookalikes, so behavioral detection and fraud monitoring matter more than waiting for a repeat package name.
2 sources covering this story
RedWing Android Spyware Sold as a Service on Telegram
Zimperium found RedWing, an Android spyware sold as a service via Telegram to target banking apps
RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service
Zimperium found RedWing, a rented Android kit that steals banking logins, lifts one-time codes, and forwards calls to defeat phone-based 2FA.
Part of the PlainSec briefing for 2026-07-08