logo

RedHook Returns with a Dangerous Upgrade

ID: 9483e68f-cbc2-525f-a770-2a41c14d32a4

STIX ID: report--9483e68f-cbc2-525f-a770-2a41c14d32a4

Feed Name: Group-IB Blog

Threat Score
75/100

Date Published: 2026-07-09

Date Updated: 2026-07-16

...
...

RedHook is an Android Remote Access Trojan that leverages Accessibility and ADB Wireless Debugging (via a Shizuku-like on-device ADB client) to escalate to shell-level (uid 2000) privileges, grant sensitive permissions (e.g., WRITE_SECURE_SETTINGS), and capture low-level input and screen data. The malware is distributed through social-engineered phishing sites and hosted APKs on public platforms (GitHub, AWS S3), targets users in Southeast Asia (notably Vietnam and Indonesia), implements robust persistence (one-pixel activity, silent audio, wake locks, mutual service resurrection, BOOT_COMPLETED auto-start, oom_score_adj), streams screens via WebSocket/RTMP, and includes expanded C2 capabilities and IOCs for defensive use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.