logo

AI-Powered Android Malware RedHat Survives Deletion and Steals Banking Credentials

ID: 39b39906-0b74-5472-a950-2c81db335d17

STIX ID: report--39b39906-0b74-5472-a950-2c81db335d17

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-09-18

Date Updated: 2026-09-19

...
...

A newly identified Android banking trojan called RedHat leverages an AI component to adapt to banking app layout changes and capture credentials and OTPs via invisible overlays, persists by reinstalling itself and blocking uninstallation, and is distributed through third-party app stores, social media, and malvertising; additionally, Cisco's ISE suffers a critical zero-day (CVE-2026-76460) that is reported to be actively exploited, and organizations are urged to patch immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.