Anyone with a few hundred dollars and a Telegram account can now run a full-scale Android bank fraud operation. No coding required.
Zimperium’s zLabs discovered an operation they’re calling RedWing. It’s a malware-as-a-service setup sold entirely through Telegram. Buyers pick a subscription tier, get referral discounts, access guides and video tutorials. A Telegram bot builds each customer a custom malicious app on demand.
The infection chain is straightforward. A phishing link sends targets to a fake app store page. The dropper builder can mimic Google Play, Samsung’s Galaxy Store, or Huawei’s AppGallery — complete with fake ratings, reviews, and download counters. If the user installs and grants permissions, the game is over.
RedWing asks for permissions one screen at a time. Disable battery optimization. Set this as your default SMS app. Turn on notifications. The big one: enable Android’s Accessibility service, which lets malware read everything on screen and simulate touches.
Once it has those permissions, RedWing can do all of the following: display fake login screens over real banking and crypto apps to steal passwords. Read incoming texts for one-time codes. Silently forward the victim’s calls to the attacker using a hidden carrier code. Stream the phone’s screen live. Log keystrokes. Turn on the camera and microphone. Steal contacts and location data. Even use the infected phone to launch DDoS attacks.
Zimperium counted 82 targeted institutions, mostly Russian financial firms. The operation appears linked to Russian threat actors.
How do you protect yourself? Only install apps from official stores. Don’t approve Accessibility access for apps that don’t need it. Watch for apps that hide their icon after installation. On managed devices, block sideloading and flag apps requesting the default-SMS role or Accessibility.
