Last updated: August 19, 2026 at 1:47 AM UTC
All 741 Vulnerability 286 Breach 129 Threat 319 Defense 7
Tag: banking-malware (2 articles)Clear

RedWing rents out ready-made Android banking malware through a Telegram bot

Zimperium found RedWing, an Android bank-fraud operation rented out on Telegram as a finished product, complete with subscription tiers, guides, and a bot that builds each buyer a custom malicious app on demand, so no coding skill is needed. It spreads through phishing links leading to fake app-store pages that convincingly imitate Google Play and other stores. Once installed and granted permissions, it overlays fake login screens on real banking and crypto apps, reads incoming texts and screen content to capture one-time codes, and can silently forward the victim's calls to defeat phone-based verification. It also offers live screen control, keylogging, and camera access.

Check
Remind users to install apps only from official stores, distrust app updates arriving by link or text, and never grant Accessibility or default-texting access to an app without a clear reason.
Affected
Android users who sideload apps and approve broad permissions; RedWing then overlays fake login screens, steals one-time codes from texts and the screen, and forwards calls to defeat phone-based verification.
Fix
Keep installs restricted to official app stores, avoid enabling unknown sources, review and limit Accessibility and default-messaging permissions, use app-based rather than SMS authentication, and deploy mobile threat defense on banking devices.

NFCShare Android malware poses as bank app updates to steal card data

Researchers at D3Lab warn that new versions of the NFCShare Android malware are spreading as fake updates for real banking apps, hosted on GitHub to look legitimate. Targeting customers of European banks, the malware shows a fake verification screen that tells victims to hold their payment card against the phone. It then uses the phone's NFC chip to read the card number, type, and expiry, and tricks the victim into typing their 4-digit PIN, sending it all to the attacker's server. That stolen data feeds NFC relay fraud, where criminals use it to make contactless payments or withdrawals. The malware only works if users sideload it.

Check
On managed Android devices, look for banking apps installed from outside Google Play and any app that requests an NFC card scan during a verification step.
Affected
Android users, mainly customers of European banks, who sideload fake banking app updates from GitHub or other non-Play sources and follow prompts to scan their cards.
Fix
Install banking apps only from Google Play, keep Play Protect enabled, and never scan a payment card or enter a PIN in response to an in-app verification prompt.