RedHook Malware Exploits Android Accessibility Features to Gain Device Control

💛 A quick favor, if you've got a second.

We're really happy that you chose to read one of our stories and sincerely hope you'll stick around to read more. We took our paywall down — for now — but that won't last forever, and when the gate goes back up, we'd love for you to already be on the inside.

It's free. So please enter your email here and don't forget to like and follow us on all of your favorite Social Media platforms!

Share this story:


✉️ Email


💬 Text

A newly discovered Android malware variant called RedHook has emerged with sophisticated capabilities to seize control of infected devices, according to cybersecurity researchers at Group-IB. The remote access trojan operates by manipulating Android’s Accessibility services and Wireless Debugging feature to achieve shell-level privileges, granting attackers far more power than standard apps typically possess. Once activated, the malware can monitor screens, record keystrokes, operate applications and extract sensitive login credentials without requiring full root access.

The attack sequence begins with social engineering tactics where criminals impersonate bank employees, government officials or technical support representatives. Victims receive calls or messages directing them to counterfeit websites mimicking legitimate banking portals or the Google Play Store interface. The malware arrives as an APK file installed from outside official channels, and once activated, prompts users to enable Accessibility permissions under the guise of account verification procedures.

RedHook exploits legitimate Android development tools to escalate its privileges. After gaining Accessibility approval, the malware systematically enables Developer Options and Wireless Debugging, then connects to the device’s own debugging interface through local address 127.0.0.1. This technique allows the trojan to leverage Android Debug Bridge functionality without requiring a physical computer connection, effectively tricking the phone into granting itself elevated system access.

Researchers identified 53 distinct commands within the current RedHook version, providing criminals extensive operational capabilities. The malware can intercept banking credentials, overlay fake login screens, remove security software and install additional malicious applications. RedHook incorporates sophisticated persistence mechanisms including silent audio processes, CPU wake locks and monitoring services that restart each other following interruptions.

Users can defend against RedHook by avoiding APK downloads from unsolicited sources and disabling app installation permissions for unknown sources in Settings. Reviewing Accessibility permissions regularly and verifying requests through official phone numbers protects against compromise. Google Play Protect scanning and current software updates provide additional safeguards, though users should remain skeptical of unexpected pressure to install applications or modify device settings.

Share this story:


✉️ Email


💬 Text