logo

RedWing Android Spyware Sold as a Service on Telegram

ID: b9b5684e-5644-5c0b-8d15-0e25210dd488

STIX ID: report--b9b5684e-5644-5c0b-8d15-0e25210dd488

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-07-08

Date Updated: 2026-07-19

...
...

Zimperium's zLabs has observed a commercially operated Android spyware strain named RedWing being marketed via Telegram as a malware-as-a-service. RedWing combines credential-harvesting overlays targeting banking and crypto apps, SMS interception and call forwarding to bypass 2FA, remote VNC control, keylogging, camera/microphone capture and DDoS capabilities; operators use obfuscated APK generation, fake app-store pages, and tutorials to enable low-skilled attackers. Researchers link it to Russian actors and note it currently evades many conventional security tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.