RedWing MaaS Turns Android Bank Fraud Into a Telegram Rental Service
RedWing lowers the barrier to cybercrime by packaging sophisticated Android banking malware as a rental service on Telegram, complete with tutorials and evasion tools, enabling even unskilled criminals to steal credentials and one-time passcodes. Victims are lured via phishing links to fake app stores where malicious apps request dangerous permissions — particularly Android Accessibility Services — giving attackers near-total device control. This matters because the MaaS model dramatically scales the threat: one skilled developer can arm hundreds of criminals simultaneously. Organizations and individuals remain vulnerable when they do not scrutinize app sources, over-grant permissions, or lack defenses against phishing-delivered malware.
Tactical Insight
Immediate actions
- Only install Android apps from official stores (Google Play) and verify publisher identity before granting any permissions.
- Deny Accessibility Service permissions to any app that is not a verified screen reader or accessibility tool.
- Enable Google Play Protect and a reputable mobile threat defense (MTD) solution on all corporate and personal devices used for banking.
Long-term improvements
- Enforce a Mobile Device Management (MDM) policy that restricts sideloading and application installation from unknown sources on all corporate-enrolled devices.
- Conduct regular phishing simulation campaigns specifically targeting mobile users to build awareness of fake app store lures.
- Implement phishing-resistant MFA (e.g., FIDO2/hardware keys) for banking and sensitive accounts so stolen OTPs cannot be used alone.
Detection measures
- Deploy mobile threat defense tools that monitor for suspicious permission grants, Accessibility Service abuse, and anomalous app behavior.
- Monitor financial accounts for unauthorized transactions and set real-time transaction alerts to detect credential misuse early.
- Share indicators of compromise (IOCs) related to RedWing/Oblivion variants with threat intelligence feeds and banking sector ISACs.