Mark RadarMARK RADAR
EN
Event File FINTECH

New RedHook Android Trojan Variant Threatens Financial Security

1 reports · First detected 2026-07-14 · Last active 2026-07-14

The RedHook Android remote-access Trojan was first detected in July 2025 and initially focused on stealing credentials. It often masquerades as websites operated by Vietnamese government agencies or financial institutions, using social engineering to trick users into downloading malware. The principal threat is its ability to give hackers complete control of a phone, allowing them to remotely operate victims' accounts and make unauthorized transfers. Although no specific loss figures are available, it already poses a direct and severe threat to bank customers' assets.

Cybersecurity firm Group-IB said in a report published on July 9, 2026, that a RedHook variant was abusing Android wireless debugging and the Shizuku tool to obtain shell-level control without root access. It currently supports 53 malicious commands, and the campaign has expanded from Vietnam to Indonesia. Experts advised financial institutions to monitor unusual ADB connections to protect users from the risk of funds being stolen.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)