logo

Telegram-Hosted RedWing Malware Lets Anyone Rent Android Spyware Tools

ID: 57e2a010-43f6-5e1d-834b-a7794e5be5f8

STIX ID: report--57e2a010-43f6-5e1d-834b-a7794e5be5f8

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2026-07-08

Date Updated: 2026-07-19

Author: Pierluigi Paganini

...
...

Zimperium’s analysis uncovered RedWing, a commercial Android spyware/MaaS distributed via Telegram that lets buyers build customized malicious APKs and rent powerful spying tools; it uses phishing to deliver fake app-store droppers, coerces dangerous permissions (Accessibility, default SMS handler, disable battery optimization), and then performs overlays to steal credentials, intercept 2FA, enable call forwarding, exfiltrate files/contacts/location, stream screens via VNC, capture audio/video, keylog, and even coordinate DDoS attacks — with operators able to reskin apps and update overlay targets from a control panel, making behavior the key detection vector.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.