RedWing Android Banking Trojan (Malware-as-a-Service)
First seen Jul 8, 2026 · Updated Jul 8, 2026
RedWing is a newly identified Android malware-as-a-service operation, rented out via Telegram for roughly $300/month, that allows low-skill attackers to take full control of victim devices, steal banking credentials, and intercept one-time passcodes (OTPs). Discovered by Zimperium's zLabs, it is believed to be a new variant of the Oblivion malware family, lowering the barrier of entry for widespread mobile banking fraud.
Technical Analysis
RedWing operates as a subscription-based mobile banking trojan distributed through underground Telegram channels, enabling affiliates to deploy device takeover capabilities, likely via Android Accessibility Service abuse, overlay attacks, and SMS/notification interception to capture OTPs and banking credentials. As a variant of Oblivion, it likely inherits obfuscation, C2 communication, and anti-analysis techniques common to the family, and is packaged for rapid customization and redeployment by non-technical operators. This significantly lowers the barrier for large-scale mobile fraud campaigns, expanding the pool of active threat actors. While primarily targeting consumer banking apps, any enterprise mobile devices used for MFA approval, banking, or credential access—including those used by staff managing AI agent platforms or API keys via mobile authenticator apps—could have session tokens, OTPs, or credentials intercepted, indirectly exposing agent-related service credentials if reused or accessed via compromised devices.
Affected Systems
Android mobile devices (versions and distribution vectors not fully disclosed in source reporting); primarily targets banking and financial applications installed on infected devices
Indicators of Compromise
- Specific hashes, C2 domains, and package names not disclosed in available reporting; associated with Oblivion malware family infrastructure and Telegram-based distribution/rental channels
Remediation Steps
- 1
Mobile Threat Defense Deployment
Deploy mobile threat defense (MTD) or endpoint security solutions capable of detecting Oblivion/RedWing behavioral patterns, including abnormal Accessibility Service usage and overlay injection.
- 2
Restrict APK Sideloading
Enforce policies preventing installation of applications from unknown sources or unofficial app stores, particularly on BYOD and corporate-managed devices.
- 3
MFA Hardening
Migrate from SMS/notification-based OTPs to hardware security keys or app-based authenticators resistant to on-device interception where feasible.
- 4
User Awareness Training
Educate employees and customers on risks of sideloaded apps, phishing links leading to fake banking apps, and suspicious permission requests.
- 5
Banking App Hardening
Financial institutions should implement root/jailbreak detection, screen overlay detection, and anomaly-based fraud detection on transaction endpoints.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.