Back to all lessons
Awareness Lessons
3 months ago

RedWing MaaS Turns Android Bank Fraud Into a Telegram Rental Service

RedWing lowers the barrier to cybercrime by packaging sophisticated Android banking malware as a rental service on Telegram, complete with tutorials and evasion tools, enabling even unskilled criminals to steal credentials and one-time passcodes. Victims are lured via phishing links to fake app stores where malicious apps request dangerous permissions — particularly Android Accessibility Services — giving attackers near-total device control. This matters because the MaaS model dramatically scales the threat: one skilled developer can arm hundreds of criminals simultaneously. Organizations and individuals remain vulnerable when they do not scrutinize app sources, over-grant permissions, or lack defenses against phishing-delivered malware.

Tactical Insight

Immediate actions

  • Only install Android apps from official stores (Google Play) and verify publisher identity before granting any permissions.
  • Deny Accessibility Service permissions to any app that is not a verified screen reader or accessibility tool.
  • Enable Google Play Protect and a reputable mobile threat defense (MTD) solution on all corporate and personal devices used for banking.

Long-term improvements

  • Enforce a Mobile Device Management (MDM) policy that restricts sideloading and application installation from unknown sources on all corporate-enrolled devices.
  • Conduct regular phishing simulation campaigns specifically targeting mobile users to build awareness of fake app store lures.
  • Implement phishing-resistant MFA (e.g., FIDO2/hardware keys) for banking and sensitive accounts so stolen OTPs cannot be used alone.

Detection measures

  • Deploy mobile threat defense tools that monitor for suspicious permission grants, Accessibility Service abuse, and anomalous app behavior.
  • Monitor financial accounts for unauthorized transactions and set real-time transaction alerts to detect credential misuse early.
  • Share indicators of compromise (IOCs) related to RedWing/Oblivion variants with threat intelligence feeds and banking sector ISACs.