New RedHook Android Trojan Variant Threatens Financial Security
The RedHook Android remote-access Trojan was first detected in July 2025 and initially focused on stealing credentials. It often masquerades as websites operated by Vietnamese government agencies or financial institutions, using social engineering to trick users into downloading malware. The principal threat is its ability to give hackers complete control of a phone, allowing them to remotely operate victims' accounts and make unauthorized transfers. Although no specific loss figures are available, it already poses a direct and severe threat to bank customers' assets.
Cybersecurity firm Group-IB said in a report published on July 9, 2026, that a RedHook variant was abusing Android wireless debugging and the Shizuku tool to obtain shell-level control without root access. It currently supports 53 malicious commands, and the campaign has expanded from Vietnam to Indonesia. Experts advised financial institutions to monitor unusual ADB connections to protect users from the risk of funds being stolen.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.