RedHook Android malware returns upgraded, targeting users across Southeast Asia

TechnologyDigital
20 Jul 2026 • 9:16 AM MYT
PriceShop Malaysia
PriceShop Malaysia

PriceShop is Malaysia's top site for news & deals for consumer electronics

Image from: RedHook Android malware returns upgraded, targeting users across Southeast Asia

A newly discovered version of the RedHook Android malware has become significantly more dangerous, with cybersecurity researchers warning that it can now abuse Android’s Wireless Debugging feature to silently gain elevated privileges on infected devices.

According to cybersecurity firm Group-IB, the latest RedHook variant doesn’t rely on an Android vulnerability but instead abuses legitimate developer features, allowing it to perform actions that normally require a computer connected via wireless Android Debug Bridge (ADB). This marks one of the first known cases of Android malware autonomously abusing wireless debugging to obtain shell-level access on a victim’s phone.

RedHook was first seen in 2025 and already had capabilities commonly associated with Android remote access trojans (RATs), including screen streaming, keylogging and stealing device credentials. However, the latest version significantly expands its capabilities, with support for 53 remote commands issued by its command-and-control server. According to Group-IB, it’s been seen in Vietnam and Indonesia, possibly targeting the Southeast Asia region.

Image from: RedHook Android malware returns upgraded, targeting users across Southeast Asia
Redhook phishing scam

The malware is typically distributed through phishing campaigns where scammers impersonate government agencies, banks or customer support representatives. Victims are persuaded via phone calls or messaging apps to download what appears to be an official Android application from fake websites designed to resemble the Google Play Store. The malicious APK files are often hosted on legitimate services such as GitHub repositories and Amazon S3 storage to improve reliability and avoid suspicion.

Once installed, RedHook tricks users into enabling Android’s accessibility service by presenting it as a necessary step for the app to function. With accessibility permissions granted, the malware can automatically navigate through settings, enable developer options, switch on wireless debugging and even complete the pairing process without a PC.

Image from: RedHook Android malware returns upgraded, targeting users across Southeast Asia
RedHook requesting permissions

Group-IB says the malware incorporates components from the popular Shizuku framework, which is commonly used by Android enthusiasts to access privileged system APIs without rooting their devices. Instead of waiting for a computer to establish an ADB connection, RedHook effectively turns the infected phone into its own ADB host, allowing it to communicate with Android’s debugging service over the device’s internal network.

With shell-level privileges, the malware can silently install or remove apps, modify secure system settings, grant itself additional permissions and capture lower-level touch input that would normally be inaccessible to standard Android apps. Bad actors with this information can then easily steal login data and hijack your sensitive information or bank account details.

Researchers also found that RedHook employs multiple persistence techniques to keep itself running, including restarting its own background services if they are terminated, launching automatically after a reboot and using foreground process tricks to reduce the likelihood of Android shutting it down to save battery.

The researchers advise users to download apps only from official app stores, avoid installing APK files received through messages or unofficial websites, and be especially cautious of apps requesting Accessibility permissions. As Android malware continues to evolve by abusing legitimate system features rather than exploiting software flaws, users are urged to treat requests for developer options and wireless debugging with the same level of suspicion.

Read more of our articles below!

Newswav Malaysia Best News App

Newswav is an online content aggregator and obtains its content from different online sources. The content in the app do not belong to Newswav nor do they reflect the opinions of Newswav and its staff. Your use of this app indicates your understanding and acceptance of this information.

Newswav Sdn. Bhd. (201701008480 (1222645-M)) 2026 All Rights Reserved