threat-intel
RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service
High
Summary
A new Android malware operation, RedWing, is being sold on Telegram as a ready-made bank fraud service. Developed by a Russian threat actor group, RedWing allows even unskilled criminals to steal banking logins and one-time codes by installing apps from unofficial sources and leveraging Accessibility features to control the device. The malware employs various techniques, including fake login screens, screen reading, and denial-of-service attacks, targeting Russian financial institutions and beyond.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
