logo

RedHook Abuses Accessibility Service to Enable Developer Options and Wireless Debugging

ID: 8ea1b03a-175c-561a-ab4e-f5f1ff9df567

STIX ID: report--8ea1b03a-175c-561a-ab4e-f5f1ff9df567

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-07-09

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

RedHook, an Android Remote Access Trojan, has resurfaced with a new capability to autonomously enable Wireless ADB via Accessibility automation and spawn a Shizuku-style shell server running as uid 2000, allowing it to grant runtime permissions, write secure settings, execute shell commands, install/uninstall apps silently, bypass MediaProjection consent for screen streaming, and exfiltrate credentials and other data. It uses resilient persistence (one-pixel activity, silent audio, WakeLocks, mutual process resurrection), social-engineering distribution via spoofed sites, and reputable hosting to improve delivery; telemetry shows expansion across Southeast Asia. The report provides file and network IOCs and advises defenders to audit Accessibility requests, monitor/block Wireless Debugging and ADB pairing, and enforce least-privilege controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.