RedWing: Android Malware-as-a-Service Spyware Operation Targeting Russian Financial Institutions

RedWing: Android Malware-as-a-Service Spyware Operation (TL-2026-1478), also tracked as RedWing MaaS, is a high-severity malware campaign, first published 2026-07-18. It is linked to a Russia-nexus actor with low confidence, affects Google Android OS (Accessibility Service / SMS Handler Role APIs), maps to 27 MITRE ATT&CK techniques (T1406, T1417, T1418), and is covered by 9 detection rules and 26 indicators of compromise.

Key facts for TL-2026-1478

Threat ID
TL-2026-1478
Also known as
RedWing MaaS, RedWing Spyware
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-07-18
Last reviewed
2026-07-18
Attribution confidence
LOW
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
finance, banking, cryptocurrency
Target regions
russia, 151 - Eastern Europe
Detection rules
9
Indicators of compromise
26

Malware and tooling in RedWing: Android Malware-as-a-Service Spyware Operation

Malware and tooling: Oblivion, RedWing

RedWing is a commercial Android spyware sold as Malware-as-a-Service (MaaS) through a Telegram-based subscription platform with tiered pricing, referral discounts, and a bot-driven APK builder. It abuses the Accessibility service and default SMS handler role to deliver banking/crypto overlay phishing, OTP interception, hidden call forwarding (*21*), live VNC screen streaming with keylogging, camera/microphone surveillance, and DDoS botnet capability, targeting 82 financial institutions with a strong focus on Russian banks.

How RedWing: Android Malware-as-a-Service Spyware Operation works

RedWing is a fully commercialized Android spyware platform documented by Zimperium zLabs (published 2026-07-07) and operated as Malware-as-a-Service via a Telegram channel and bot. Customers subscribe through tiered pricing plans with a referral program that discounts fees for distributors who recruit new buyers. A Telegram bot automates APK construction: it packages a customer-selected target list of banking/crypto apps, injects an obfuscated dropper, and mimics legitimate app store listings (Google Play, Samsung Galaxy Store, Huawei AppGallery, and Russia's RuStore) complete with forged reviews, download counts, and metadata to lower victim suspicion.

Once installed, the dropper decrypts a second-stage DEX payload from its assets at runtime and requests a sequence of permissions through a fake onboarding flow modeled on legitimate app UX: battery-optimization exemption, default SMS handler role, notification access, device admin, and — critically — Android's Accessibility service, which the malware abuses to read screen content, inject synthetic touch/input events, and dismiss competing prompts. With Accessibility and SMS-handler access established, RedWing deploys fake login overlays (fake activity windows drawn over legitimate banking and cryptocurrency apps) to harvest credentials, PINs, and patterns, and uses regex-based scanning of intercepted SMS/notification text to grab one-time passcodes, card numbers, and CVV codes in real time before forwarding them to the operator panel.

Beyond credential theft, RedWing gives the operator a live VNC-style remote-control channel over the infected device: real-time screen streaming, keystroke logging, and remote command execution (e.g., triggering photo capture or audio recording) through an operator control panel that also exposes real-time device telemetry and lets operators update overlay target lists without re-issuing the APK. A hidden call-forwarding feature abuses the legacy USSD carrier code (*21*) to silently redirect the victim's incoming voice calls to attacker-controlled numbers, defeating voice-based 2FA and bank verification calls, while incoming calls from the victim's bank can be silenced outright. The platform additionally offers a DDoS-for-hire capability: RedWing-infected devices can be pooled into a botnet that issues coordinated multi-threaded HTTP floods against operator-specified targets.

Zimperium assesses RedWing shares droppers and overlay techniques with the previously tracked Oblivion Android malware family, indicating RedWing is a MaaS-commercialized evolution/variant rather than a wholly new codebase. Because APKs are compiled server-side per customer/campaign with a dynamically selected target list and bot-driven obfuscation, static hash-based detection is undermined; Zimperium published a rolling IOC set (APK hashes, phishing domains, and dropper distribution sites) rather than a single canonical sample. The operation shows links to Russian-speaking threat actors and disproportionately targets Russian financial institutions alongside a smaller set of international banks and crypto exchanges, distributed through phishing sites that impersonate legitimate app stores and cloud-storage services (e.g., a fake Yandex Disk page) to seed the initial dropper download.

MITRE ATT&CK techniques used in TL-2026-1478

defense-evasion

T1406 Obfuscated Files or Information; T1516 Input Injection; T1628 Hide Artifacts; T1630 Indicator Removal on Host

collection

T1417 Input Capture; T1517 Access Notifications

Discovery

T1418 Software Discovery; T1426 System Information Discovery; T1430 Location Tracking

Collection

T1429 Audio Capture; T1512 Video Capture; T1513 Screen Capture; T1533 Data from Local System; T1636 Protected User Data

command-and-control

T1437 Application Layer Protocol; T1663 Remote Access Software

initial-access

T1474 Supply Chain Compromise; T1660 Phishing

Persistence

T1541 Foreground Persistence

Impact

T1582 SMS Control; T1616 Call Control; T1641 Data Manipulation; T1642 Endpoint Denial of Service

Resource Development

T1583 Acquire Infrastructure; T1587 Develop Capabilities

persistence

T1624 Event Triggered Execution

stealth

T1684.001 Impersonation

Affected products and versions in RedWing: Android Malware-as-a-Service Spyware Operation

  • Google — Android OS (Accessibility Service / SMS Handler Role APIs)
    Vulnerable versions: Android 9 and later (abuse of standard APIs, not a version-specific flaw)
  • Multiple — Banking and cryptocurrency mobile applications (82 targeted institutions)
    Vulnerable versions: All versions vulnerable to overlay/phishing attack technique

Remediation for RedWing: Android Malware-as-a-Service Spyware Operation

Patches

  • No vendor CVE/patch applicable — this is a social-engineering-delivered spyware app, not a platform vulnerability
  • Ensure Android build participates in Google Play Protect and has the latest Play Protect signature updates

Immediate actions

  • Block installation from unknown sources (sideloading) on managed Android fleets via MDM policy
  • Block outbound traffic to RedWing-associated domains and dropper distribution sites at DNS/proxy layer
  • Audit devices for apps holding both Accessibility service AND default-SMS-handler role simultaneously; this pairing is a strong RedWing/Oblivion-family indicator
  • Alert on USSD calls containing *21* (unconditional call forwarding activation) originating from banking-app-adjacent processes
  • Instruct banking customers to verify APKs only via official Google Play / Galaxy Store / AppGallery listings, never via shared links or QR codes

Workarounds

  • Disable 'install from unknown sources' at the OS/MDM level
  • Restrict Accessibility service grants to an enterprise allowlist via MDM
  • Disable call forwarding at the carrier level for high-risk banking customers where feasible

Longer-term hardening

  • Deploy mobile threat defense (MTD/EDR) with behavioral detection for Accessibility-service abuse and overlay injection
  • Move 2FA away from SMS/voice OTP toward app-based or hardware-token authentication for banking customers
  • Implement app-attestation / Play Integrity API checks server-side for banking apps to detect compromised or emulator/rooted execution environments
  • Threat-hunt for Oblivion-family dropper indicators across the wider mobile fleet given shared codebase lineage
  • Establish continuous phishing-domain monitoring for typosquats of banking/app-store brands

Weaknesses (CWE) in RedWing: Android Malware-as-a-Service Spyware Operation

CWE-451, CWE-359, CWE-287, CWE-319

Timeline of RedWing: Android Malware-as-a-Service Spyware Operation

  • Estimated ongoing distribution period preceding public disclosure, based on Zimperium's dataset of dropper APKs and phishing sites collected across the campaign.
  • Zimperium publishes a companion resource page summarizing zLabs' findings on the RedWing MaaS platform for broader distribution.
  • Zimperium publishes accompanying IOC repository on GitHub containing dropper APK hashes and phishing/distribution domains for RedWing.
  • Zimperium zLabs publishes initial technical blog disclosing the RedWing Android spyware MaaS operation, its Telegram bot distribution model, and full command/capability set.
  • PCrisk publishes a consumer-facing removal and recovery guide for RedWing-infected Android devices.
  • The420.in publishes follow-on analysis highlighting the hidden USSD *21* call-forwarding feature used to intercept voice-based 2FA from banks.
  • Infosecurity Magazine, The Hacker News, and Security Affairs publish independent coverage summarizing Zimperium's RedWing findings, expanding public awareness of the Telegram-based rental model.
  • TL-Intel Harness RESEARCH phase completed for TL-2026-1478, consolidating multi-source reporting and IOC data into structured threat intelligence.

Sources cited for RedWing: Android Malware-as-a-Service Spyware Operation

Threats related to RedWing: Android Malware-as-a-Service Spyware Operation

Detection coverage for TL-2026-1478

As of 2026-07-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1478 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats