Particle.news
Download on the App Store

RedWing Malware Is Sold as a Telegram Rental Service

Researchers warn the kit uses install-time social engineering to win Android permissions that let low-skill buyers take full control of victims’ phones.

Overview

  • Zimperium’s zLabs disclosed this week that RedWing is a commercial Malware-as-a-Service offered on Telegram with subscription tiers, tutorial videos, referral discounts, and a bot that builds custom malicious APKs on demand.
  • Customers are lured with phishing links to fake app-store pages that coax users into sideloading a dropper and approving staged permission prompts disguised as routine setup.
  • Once installed and granted Accessibility, default-SMS, notification and battery-exemption permissions, RedWing can deploy fake login overlays, read one-time SMS codes, keylog, stream the screen live, and access camera and microphone.
  • The malware can also silently enable call forwarding to attacker numbers to defeat phone-based two-factor checks, steal files and contacts, and pool infected phones for coordinated denial-of-service attacks.
  • Defenders are urged to block sideloading on managed devices, flag or prevent requests for Accessibility and default-SMS roles, use behavior-based detection and published indicators of compromise, and educate users against installing apps from links.