hacker-news · Crawled Jul 7, 2026
RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service
Read original article ↗AI Summary
RedWing is a new Android malware-as-a-service (MaaS) operation rented via Telegram, enabling low-skilled attackers to conduct bank fraud. It delivers ready-made payloads that bypass security tools and use phishing links to trick users into installing malicious apps from unofficial sources. The malware abuses Android Accessibility services to steal banking credentials, intercept one-time codes, and enable real-time remote control of infected devices. It primarily targets Russian financial institutions and operates through custom-built droppers with dynamically configurable overlay attacks.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.