Find notable cyber news and cases, enriched with sources, timelines, and signals.

RedWing Android spyware rented through Telegram

Malware Activity
First reported
Last updated
Happening score
H score 21
1 unique sources, 1 articles

Summary

Hide ▲

The RedWing Android spyware operation is being rented through Telegram, lowering the barrier for criminals to hijack phones and steal banking credentials. The malware uses fake app-store pages and permission prompts to land on Android devices. It can intercept 2FA codes, forward calls, hide its icon, and provide live VNC control, keylogging, and audio/video recording. Infected phones can also be pooled for DDoS abuse.

Related Happenings

RedHook Android malware abuses Wireless ADB for shell access

Malware Activity
H score26 First: 12.07.2026 17:27 Last: 12.07.2026 17:27 Sources 1

About this happening: The RedHook Android malware now abuses Wireless ADB to obtain shell (UID 2000) privileges, expanding its control over infected devices. The change lets the malware ope...

RedWing Android bank-fraud malware rental service

Malware Activity
H score21 First: 07.07.2026 20:10 Last: 07.07.2026 20:10 Sources 1

About this happening: The RedWing Android malware service is being rented on Telegram to steal banking logins, OTPs, and device control, raising fraud risk for banking and cryptocurre...

Google Play Protect adds warnings and app disabling for compromised SDK abuse

Security Tool/Service
H score11 First: 03.07.2026 12:35 Last: 03.07.2026 12:35 Sources 1

About this happening: Google Play Protect was updated in July 2026 to warn Android users automatically and disable apps tied to compromised SDKs, limiting abuse of consumer devices...

BTMOB Android MaaS platform expands low-code phishing payload production

Threat Actor Meta
H score21 First: 29.05.2026 00:10 Last: 29.05.2026 00:10 Sources 1

About this happening: BTMOB has been exposed as a malware-as-a-service Android trojan with a builder interface, making it easier for cybercriminals to mass-produce tailored phishing payload...

Grandoreiro and BTMOB banking trojan activity targeting Windows and Android

Malware Activity
H score25 First: 27.05.2026 19:10 Last: 27.05.2026 19:10 Sources 1

About this happening: BTMOB is an Android remote access trojan sold as malware-as-a-service on the clearweb and in private Telegram channels, with a builder that generates customize...

Timeline

  1. 08.07.2026 18:30 2 articles · 13d ago

    RedWing Android spyware sold as a service on Telegram

    Initial Disclosure

    Researchers at Zimperium zLabs named RedWing, an Android spyware-as-a-service operation sold through Telegram with seller documentation, tutorial videos, and a subscription model. The kit uses a Telegram bot to build and obfuscate malicious APKs, fake app-store pages that mimic Google Play, the Galaxy Store, AppGallery, and RuStore, and permission prompts to gain access such as Android's accessibility service and the SMS inbox, enabling credential theft from banking and cryptocurrency apps, SMS 2FA interception, call forwarding, VNC control, keylogging, and camera and microphone recording.

    Show sources