logo

RedHook Android malware now uses Wireless ADB for shell access

ID: d5a8383a-3d5a-5201-a5b3-f5ac20867325

STIX ID: report--d5a8383a-3d5a-5201-a5b3-f5ac20867325

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-07-12

Date Updated: 2026-07-19

Author: Bill Toulas

...
...

Group-IB analyzed a new RedHook Android malware variant that autonomously enables Wireless ADB by abusing Accessibility permissions, then pairs to the device’s ADB service via loopback and runs Shizuku to execute shell-level (UID 2000) commands without root; it retains comprehensive RAT features (screen streaming, keystroke capture, UI automation, credential theft), multiple persistence techniques, and is distributed via social-engineered fake Google Play sites, representing a serious mobile threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.