logo

RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service

ID: b02e4153-415d-5cbc-8bf4-c408eaa7342b

STIX ID: report--b02e4153-415d-5cbc-8bf4-c408eaa7342b

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-07-07

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

**RedWing** is a commercial Android malware-as-a-service distributed via Telegram that enables low-skill criminals to perform on-device banking fraud by using phishing-based sideloads, Accessibility abuse, fake overlays, SMS/OTP interception, call forwarding, live screen streaming, keylogging, and data exfiltration; researchers (zLabs) observed evasion of conventional security tools and a targeting list of at least 82 institutions, with strong ties to the Russian market.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.