RedWing is an Android spyware operation sold as a Malware-as-a-Service offering and distributed through Telegram-supported criminal infrastructure. It is designed to lower the barrier to entry for operators by providing subscription-based access to customizable malicious APK generation, obfuscation, onboarding flows, and centralized victim management. RedWing has been assessed as likely related to, or evolved from, the Oblivion malware family based on similarities in its dropper and overlay components, and reporting has noted links or apparent ties to Russian threat actors, although precise attribution remains unconfirmed.
RedWing is primarily delivered through mobile phishing pages that impersonate legitimate Android app stores and persuade victims to sideload malicious applications. Its infection flow relies on staged social engineering rather than exploitation of Android vulnerabilities. Victims are guided into granting high-risk permissions and roles, including Accessibility access, notification access, overlay privileges, device administration, battery optimization exemptions, and default SMS handler status. The malware abuses these legitimate Android features to gain deep visibility and control over the device.
Once installed, RedWing supports extensive surveillance, credential theft, and fraud-enablement functions. It can steal SMS messages, contacts, call logs, files, photos, and device metadata; intercept one-time passcodes; perform real-time keylogging; and use Accessibility and overlay mechanisms to harvest banking and cryptocurrency credentials, payment card data, PINs, and other sensitive information. It can also manipulate the device through simulated user actions, launch deceptive overlays, open applications, and update targeting and phishing injects from its control panel without requiring redistribution of a new sample.
RedWing also provides remote-control and post-compromise capabilities including live screen streaming via VNC-style functionality, screen capture, remote screen locking, microphone activation, camera activation, location access, proxy tunneling, and call-forwarding abuse to bypass voice-based authentication and fraud checks. In addition to espionage and financial theft functions, it can conscript infected devices into coordinated HTTP flood attacks, giving the operation botnet-style DDoS capability.
The malware communicates with a centralized command-and-control panel over HTTP and WebSocket and reportedly exposes a large command set for surveillance, device control, injection management, proxy session handling, and denial-of-service operations. Targeting observed for RedWing shows a strong emphasis on financial institutions, particularly Russian banks and cryptocurrency-related services, indicating a pronounced financial-crime orientation on Android devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
On top of that, operators get... access to all files on the device, contact lists, call logs, and location tracking.
On top of that, operators get live screen streaming via VNC, a real-time keylogger, access to all files on the device...
It deploys fake login screens over real banking and crypto apps to steal credentials...
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android spyware/RAT offered as Malware-as-a-Service via Telegram. It supports data exfiltration (SMS, contacts, call logs, files, photos), real-time screen streaming via VNC, keylogging, banking and crypto overlays, 2FA interception, audio/video capture, DDoS, proxy tunneling, and dynamic encrypted DEX loading for evasion.
Android malware sold as a MaaS offering via Telegram. It uses phishing-linked fake app store pages and custom droppers to trick users into sideloading malicious apps, abuses Accessibility, default SMS handler, and notification permissions, steals banking and crypto credentials via overlays, intercepts SMS 2FA codes, captures PIN/card/CVV data, enables call forwarding, supports remote camera/microphone activation, live screen streaming via VNC, keylogging, file/contact/call-log/location theft, and can also turn infected devices into a DDoS-capable botnet.
Android banking malware sold as a subscription service via Telegram. It uses phishing-delivered droppers, staged permission abuse, Accessibility abuse, SMS interception, overlay attacks, call forwarding, live screen streaming, keylogging, remote device control, camera/microphone access, file/contact/call-log theft, location tracking, and can also use infected devices for denial-of-service activity.
Android MaaS spyware with remote-control and credential-theft capabilities. It exfiltrates SMS, contacts, call logs, files, and device metadata; uses overlays to steal banking and cryptocurrency credentials; supports VNC-style live screen control, keylogging, camera/microphone capture, call forwarding abuse, and can launch DDoS attacks from infected devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.