← All articles

RedHook Android malware abuses wireless debugging to seize shell-level control

Group-IB detailed a new version of the RedHook Android banking trojan that gains shell-level control of a phone by abusing the operating system's own wireless debugging feature, with no computer or root needed. Once a user is tricked into granting Accessibility permissions, the malware silently taps through Settings to enable Developer Options and Wireless Debugging, then pairs over the loopback interface to run privileged commands. From there it can silently install or remove apps, change secure settings, log keystrokes, stream the screen, and steal credentials, while an aggressive persistence stack keeps it running through reboots. It spreads through social engineering, with attackers impersonating government or bank staff.

Check
Remind users to install Android apps only from official stores, distrust calls or messages urging them to install an app or enable Accessibility, and review which apps hold Accessibility permissions.
Affected
Android users tricked into sideloading the malware and granting Accessibility; RedHook then enables wireless debugging to gain shell-level privileges, letting it control the device, steal banking credentials, and resist removal.
Fix
Keep installs restricted to official app stores with Play Protect enabled, treat Accessibility requests with suspicion, and for organizations, monitor or block wireless-debugging activation and enforce mobile threat defense on banking devices.