RedHook Abuses Accessibility Service to Enable Developer Options and Wireless Debugging
ID: 8ea1b03a-175c-561a-ab4e-f5f1ff9df567
STIX ID: report--8ea1b03a-175c-561a-ab4e-f5f1ff9df567
Feed Name: GBHackers
RedHook, an Android Remote Access Trojan, has resurfaced with a new capability to autonomously enable Wireless ADB via Accessibility automation and spawn a Shizuku-style shell server running as uid 2000, allowing it to grant runtime permissions, write secure settings, execute shell commands, install/uninstall apps silently, bypass MediaProjection consent for screen streaming, and exfiltrate credentials and other data. It uses resilient persistence (one-pixel activity, silent audio, WakeLocks, mutual process resurrection), social-engineering distribution via spoofed sites, and reputable hosting to improve delivery; telemetry shows expansion across Southeast Asia. The report provides file and network IOCs and advises defenders to audit Accessibility requests, monitor/block Wireless Debugging and ADB pairing, and enforce least-privilege controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
