Overview
- Zimperium’s zLabs disclosed this week that RedWing is a commercial Malware-as-a-Service offered on Telegram with subscription tiers, tutorial videos, referral discounts, and a bot that builds custom malicious APKs on demand.
- Customers are lured with phishing links to fake app-store pages that coax users into sideloading a dropper and approving staged permission prompts disguised as routine setup.
- Once installed and granted Accessibility, default-SMS, notification and battery-exemption permissions, RedWing can deploy fake login overlays, read one-time SMS codes, keylog, stream the screen live, and access camera and microphone.
- The malware can also silently enable call forwarding to attacker numbers to defeat phone-based two-factor checks, steal files and contacts, and pool infected phones for coordinated denial-of-service attacks.
- Defenders are urged to block sideloading on managed devices, flag or prevent requests for Accessibility and default-SMS roles, use behavior-based detection and published indicators of compromise, and educate users against installing apps from links.