RedHook: A New Android Banking Trojan Targeting Users In Vietnam
ID: a10a6e4b-fab7-54b4-a2db-6e334596d4dd
STIX ID: report--a10a6e4b-fab7-54b4-a2db-6e334596d4dd
Feed Name: Cyble Blog
Threat Score
RedHook is a newly discovered Android banking trojan targeting Vietnamese users via spoofed government and banking websites that distribute malicious APKs; it abuses accessibility and overlay permissions, uses WebSocket-based RAT connectivity (skt9/api9 domains), supports 34 remote commands, captures screens via MediaProjection, keylogs, exfiltrates credentials and images to an exposed AWS S3 bucket, and has low antivirus detection with evidence of hundreds of infections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
