CyberSecurityBoardThreat Intel · CVEs · Products
Malware

RedWing MaaS: Android Banking Malware Sold as Telegram Rental Service

July 7, 2026

A new Android malware operation called RedWing is being offered as a ready-made bank-fraud service on Telegram, allowing low-skill criminals to take over victims’ phones, steal banking credentials, and intercept one-time codes. Discovered by Zimperium’s zLabs, RedWing is a variant of the Oblivion rent-a-malware tool and is sold in subscription tiers with referral discounts, guides, and how-to videos. A Telegram bot builds custom apps on demand, and many droppers and payloads currently evade conventional security tools.

Infection begins with a phishing link leading to a fake app-store page mimicking Google Play, Galaxy Store, or AppGallery, complete with fake ratings and reviews. The app requests permissions one at a time, including Accessibility service, default SMS handler, and battery exemption, granting broad control. Capabilities include fake login overlays for banking and crypto apps, reading SMS one-time passcodes, silent call forwarding using carrier codes, live screen streaming, keylogging, camera/microphone activation, file theft, location tracking, and DDoS attacks. Buyers choose targets, with Accessibility-watched apps baked into each copy and overlays changeable via a control panel.

Zimperium identified 82 targeted institutions, heavily focused on Russian financial firms, with evidence pointing to Russian threat actors. RedWing fits the trend of on-device fraud, similar to Fantasy Hub, Albiriox, and Klopatra. No Android exploit is needed; defense relies on users avoiding sideloading and suspicious permissions. Indicators of compromise have been published, but the malware’s reskinning capability makes behavior the key signal.

CVEs: CVE-2026-55200, CVE-2026-46817

Malware: RedWing, Oblivion, Fantasy Hub, Albiriox, Klopatra

Companies: Zimperium