The images in this article were generated with artificial intelligence. How we publish
The malicious operation known as RedWing It represents a dangerous evolution in the mobile cybercrime industry: it is not just another technical Trojan, but a "ready-to-use" product that is sold and distributed through open channels such as Telegram, which drastically reduces the technical barrier to bank fraud. Zimperium zLabs researchers have documented how this kit combines an automated application builder with fake store templates, video guides and a control panel that allows buyers with no advanced knowledge to design droppers and payloads as they are, in many cases, able to evade conventional defenses.
The business model - subscriptions, referrals and delivery on demand through a Telegram bot - transforms the threat from being a tool of specialized groups to service to which any offender with a willingness to pay can access. That approach is not new, but the sophistication of deception is. The installers and download pages are presented as legitimate stores (Google Play, Galaxy Store, AppGallery or full copies), with false reviews and counters, and lead the victim to allow off-site facilities and to grant sensitive permits in a phased manner to reduce suspicion.

The technical danger comes when the malicious application gets permissions like the service of Accessibility, the ability to become default SMS manager and the battery saving exemption. With these privileges, RedWing can present false overlay on bank apps to steal credentials at the point of use, read or intercept single-use codes (OTP), activate call deviations using hidden codes (* 21 *), perform real-time screen streaming, record keys, access to camera and microphone, steal contacts and location, and even coordinate infected devices for service denial attacks against selected targets.
From a risk perspective, there are three relevant changes that organizations and users need to understand: first, the goal is no longer just to steal credentials for use in a remote site; now the attackers operate within the bank session on the victim device, which makes many countermeasures based on "changing the password" insufficient. Second, the rotation and reskin of the kit (the names of the apps change, but the behavior persists) complicates detection based on static signatures. Third, marketing on platforms such as Telegram and the availability of training materials increase the scale and diversity of actors who can launch these campaigns.
The operational implications for financial institutions are severe: it will increase fraud in live sessions, grow false positive and pressure on customer care and fraud equipment, and it becomes critical to strengthen detection that does not depend only on the validity of the password or SMS. From a regulatory and policy point of view, these attacks force the adoption of strong authentication mechanisms that do not depend on easy-to-intercept channels and require better installation controls and Android permissions.
For private users, the first line of defence is to prevent initial installation. Do not install apps from links sent by SMS or messaging, do not activate "unknown origins" and distrust updates received by message. Do not grant an app access permits, default SMS role or battery exemption unless there is a clear and verifiable justification. If an application hides its icon after installation, or requests permissions on several emerging screens while showing only one "harmless" website, it should be removed and reported immediately. It is recommended to use modernized authentication applications (FIDO code-generating apps or keys) rather than relying on SMS for OTP, and keep the operating system and security solutions up-to-date.
In corporate and government-managed environments, concrete measures include imposing MDM / EMM policies that block the sideloading, applying white application lists, restricting the use of the Accessibility service to approved apps, monitoring roles such as default SMS app and detecting call diversion settings. It is also critical to implement mobile telemetry to alert about abnormal behaviors: apps that ask to become SMS manager, processes that can overlap windows over other apps, unexpected screen streaming or repeated access to the camera / microphone without user interaction.
In threat hunting, it is appropriate to focus on behavior and not names: to search for enabled Accessibility permit events, changes in default SMS application, presence of background services that do not show icon, attempts to modify battery saving policies and evidence of outgoing calls with diversion activation codes. Technical indicators and samples published by response teams (such as Zimperium's) help, but you have to expect variants and reskins: the signature is the behavior, not the name of the package.

In addition to technical actions, there is a collaborative dimension: messaging platforms and application markets should tighten the mechanisms to detect and close channels that trade with malware; financial institutions should improve real-time fraud telemetry and adopt device-resistant authentication methods; and public security teams should prioritize the investigation and dismantling of these illicit economies in Telegram and similar marketers.
If you want to deepen the technical mitigation recommendations for Android and understand good mobile security practices, see the official Android security documentation at https: / / developer.android.com / security and the media coverage that documents the availability of these kits on public platforms, for example on BleepingComputer. It is also recommended to follow zLabs publications for indicators and technical details: https: / / blog.zimperium.com /.
In short, RedWing is a reminder that mobile security is not just a technical but a social and economic issue: as long as markets exist that professionalize and disseminate fraud tools, the risk will grow. The best defense combines preventive controls at the time of installation, technical policies on managed devices, authentication that does not depend on SMS and closer collaboration between platforms, banks and law enforcement.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...