RedHook Android malware now uses Wireless ADB for shell access
ID: d5a8383a-3d5a-5201-a5b3-f5ac20867325
STIX ID: report--d5a8383a-3d5a-5201-a5b3-f5ac20867325
Feed Name: Bleeping Computer
Group-IB analyzed a new RedHook Android malware variant that autonomously enables Wireless ADB by abusing Accessibility permissions, then pairs to the device’s ADB service via loopback and runs Shizuku to execute shell-level (UID 2000) commands without root; it retains comprehensive RAT features (screen streaming, keystroke capture, UI automation, credential theft), multiple persistence techniques, and is distributed via social-engineered fake Google Play sites, representing a serious mobile threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
