← All news

general

RedWing: Android Banking Trojan Rented Out on Telegram

2026-07-09

There's a new Android spyware in circulation, and the interesting thing about it isn't the malware itself. It's the shopfront.

Researchers at Zimperium's zLabs team have named it RedWing, and they describe it less as a piece of code and more as a small business. It runs through Telegram with a proper malware-as-a-service setup: seller documentation, tutorial videos, subscription tiers, and a referral scheme that hands out discounts to customers who bring in more customers. Zimperium links the operation to Russian threat actors and believes it's a fresh cut of an older family known as Oblivion.

Point, click, deploy

Getting started is almost insultingly easy. A Telegram bot builds and obfuscates the malicious APK for the buyer, then generates fake app-store listings that impersonate Google Play, the Galaxy Store, AppGallery, or Russia's RuStore. The pages come pre-loaded with invented review counts and download numbers to lend a bit of theatre.

Once a victim installs the app, RedWing walks them through what looks like a normal setup process, quietly steering them into granting Android's accessibility service and SMS permissions along the way. Then the app icon vanishes and the real work starts.

Overlays, SMS, and a clever call trick

The malware targets 82 banking and cryptocurrency apps, mostly belonging to Russian financial firms. When the victim opens one of them, RedWing slides a convincing fake login screen over the top and captures the credentials as they're typed.

Two-factor authentication doesn't slow it down much. It intercepts SMS codes, and it can silently forward incoming calls to the attacker, which neatly defeats the confirmation calls some banks make when a transaction looks unusual. Beyond that, the toolkit includes:

  • Live VNC-style remote screen control
  • Keylogging
  • Covert camera and microphone recording
  • A module to enrol the infected phone into a DDoS botnet

All of that sits behind a subscription button.

The market is the story

Individually, none of these capabilities are new. Overlay attacks, SMS interception, VNC modules and covert recording have been features of Android banking malware for years. What's changed is who can get their hands on them.

When a working banking trojan ships with onboarding videos, tiered pricing and a friend-referral discount, the effort required to run one drops to roughly the effort of signing up for a streaming service. You no longer need to know how the malware works, or how to distribute it, or how to build a convincing fake store page. The kit does all of that for you.

That shifts the population of people running these campaigns. Previously, the operators tended to be at least reasonably capable, which meant the campaigns had a certain shape and pace. When the barrier drops this far, the wheel gets handed to people who are enthusiastic rather than careful, and the campaigns get noisier, broader, and harder to predict.

The technical side of RedWing is worth knowing about. The business model behind it is worth thinking about for a bit longer.

RedWing: Android Banking Trojan Rented Out on Telegram | RiskSense