logo

RedHook: A New Android Banking Trojan Targeting Users In Vietnam

ID: a10a6e4b-fab7-54b4-a2db-6e334596d4dd

STIX ID: report--a10a6e4b-fab7-54b4-a2db-6e334596d4dd

Feed Name: Cyble Blog

Threat Score
76/100

Date Published: 2025-08-25

Date Updated: 2026-07-16

...
...

RedHook is a newly discovered Android banking trojan targeting Vietnamese users via spoofed government and banking websites that distribute malicious APKs; it abuses accessibility and overlay permissions, uses WebSocket-based RAT connectivity (skt9/api9 domains), supports 34 remote commands, captures screens via MediaProjection, keylogs, exfiltrates credentials and images to an exposed AWS S3 bucket, and has low antivirus detection with evidence of hundreds of infections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.