highMalware

RedWing Android Banking Trojan (Malware-as-a-Service)

First seen Jul 8, 2026 · Updated Jul 8, 2026

androidbanking-trojanmaastelegrammobile-malwarecredential-theftotp-interceptionoblivion-variant

RedWing is a newly identified Android malware-as-a-service operation, rented out via Telegram for roughly $300/month, that allows low-skill attackers to take full control of victim devices, steal banking credentials, and intercept one-time passcodes (OTPs). Discovered by Zimperium's zLabs, it is believed to be a new variant of the Oblivion malware family, lowering the barrier of entry for widespread mobile banking fraud.

Technical Analysis

RedWing operates as a subscription-based mobile banking trojan distributed through underground Telegram channels, enabling affiliates to deploy device takeover capabilities, likely via Android Accessibility Service abuse, overlay attacks, and SMS/notification interception to capture OTPs and banking credentials. As a variant of Oblivion, it likely inherits obfuscation, C2 communication, and anti-analysis techniques common to the family, and is packaged for rapid customization and redeployment by non-technical operators. This significantly lowers the barrier for large-scale mobile fraud campaigns, expanding the pool of active threat actors. While primarily targeting consumer banking apps, any enterprise mobile devices used for MFA approval, banking, or credential access—including those used by staff managing AI agent platforms or API keys via mobile authenticator apps—could have session tokens, OTPs, or credentials intercepted, indirectly exposing agent-related service credentials if reused or accessed via compromised devices.

Affected Systems

Android mobile devices (versions and distribution vectors not fully disclosed in source reporting); primarily targets banking and financial applications installed on infected devices

Indicators of Compromise

  • Specific hashes, C2 domains, and package names not disclosed in available reporting; associated with Oblivion malware family infrastructure and Telegram-based distribution/rental channels

Remediation Steps

  1. 1

    Mobile Threat Defense Deployment

    Deploy mobile threat defense (MTD) or endpoint security solutions capable of detecting Oblivion/RedWing behavioral patterns, including abnormal Accessibility Service usage and overlay injection.

  2. 2

    Restrict APK Sideloading

    Enforce policies preventing installation of applications from unknown sources or unofficial app stores, particularly on BYOD and corporate-managed devices.

  3. 3

    MFA Hardening

    Migrate from SMS/notification-based OTPs to hardware security keys or app-based authenticators resistant to on-device interception where feasible.

  4. 4

    User Awareness Training

    Educate employees and customers on risks of sideloaded apps, phishing links leading to fake banking apps, and suspicious permission requests.

  5. 5

    Banking App Hardening

    Financial institutions should implement root/jailbreak detection, screen overlay detection, and anomaly-based fraud detection on transaction endpoints.

Industries Most Exposed

financial servicesbankingmobile telecommunicationsretail consumers

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.