RedHook Android Trojan Automatically Enables Wireless ADB Debugging to Hijack Devices Without Root or User Interaction
The RedHook trojan, first described in July 2025, has received an unprecedented update that lets it independently enable wireless ADB debugging on compromised Android smartphones, achieving system-shell privileges without root or any action from the victim.
According to researchers at Group-IB, the infection follows a familiar social-engineering pattern. Attackers contact targets by phone or messenger, posing as bank or government representatives, and persuade them to download an application from a fake website styled to resemble an official app store. The malicious APK files themselves are hosted on legitimate infrastructure—GitHub repositories and Amazon S3 cloud storage—reducing the likelihood of detection by security solutions.
After installation, victims are convinced to grant the app accessibility-service permissions under the pretext of enabling full functionality. This single permission serves as the gateway to everything else. With accessibility access, RedHook automatically opens the device settings, taps the build number seven times to reveal the developer menu, and activates wireless debugging—all hidden behind a full-screen overlay.
The malware then runs its own ADB client, which connects directly to the phone’s local debugging server using the loopback address, eliminating any need for an external computer. The technique is built on code from the popular Shizuku framework that advanced users normally employ to extend app capabilities without root.
Once system-level privileges are obtained, RedHook can silently install or remove applications, alter protected settings, and grant itself additional permissions without triggering confirmation dialogs. To remain active as long as possible, the trojan employs several anti-termination tactics: it simulates an active foreground window, plays silent audio, prevents the CPU from sleeping, and blocks the system from killing its process under low-memory conditions.
Two service processes monitor each other and restart their counterpart if either is stopped. After a device reboot, a dedicated component automatically restores all privileges. Stolen data and live screen recordings are transmitted over encrypted connections to attacker-controlled servers; when system rights are already present, the malware can stream the screen without triggering the standard screen-recording permission prompt.
Observed campaigns remain focused on Southeast Asia, with infections confirmed in Vietnam and later in Indonesia. Experts advise installing applications exclusively from official stores, scrutinizing permission requests—especially accessibility access—and remaining wary of unsolicited contacts claiming to represent banks or government agencies.
Related articles
Attackers Abuse Legitimate Microsoft Defender Exclusions to Conceal Malware
Huntress researchers have detailed an evasion technique in which threat actors avoid disabling Microsoft Defender entirely. Instead, they create targeted exclusions for specific folders or file extensions, allowing malware to operate undetected while the protection status remains apparently active. These exclusions are configured through PowerShell commands, Windows Management Instrumentation, Group Policy, or direct registry modifications, all requiring administrator privileges after initial compromise. A registry key named HideExclusionsFromLocalAdmins can further conceal the list of exclusions from local administrators viewing the interface. The approach has been linked to campaigns involving GootKit in 2019, WhisperGate in 2022 that excluded the entire C: drive, and Muddled Libra in 2024. Defenders are advised to monitor registry changes directly, as this bypasses interface hiding, and to flag exclusions of entire drives or common directories such as temporary and downloads folders.
SC Malware on WordPress Restores Deleted Backdoors in Seconds via Eight Persistence Points
Researchers at Sucuri have analyzed the SC malware targeting WordPress sites, which rapidly restores any removed backdoor components through a minimum of eight interconnected persistence mechanisms. The infection hides across PHP configuration settings, hidden loaders, theme files, and plugins, with some elements executing before standard WordPress plugins load. Copies of the malicious code are also stored in the database and System V shared memory on supported servers, allowing full reinfection from surviving sources after file cleanup. The backdoor evades plugin listings, gathers site and administrator session data, deploys additional PHP code, and disables security plugins while injecting JavaScript for payment data theft in online stores. Command-and-control occurs through public Ethereum RPC gateways and smart contracts with multiple fallback channels. Sucuri warns that PHP caching of the loader directive can crash request handling if the referenced file is deleted without prior preparation, and recommends a sequenced cleanup process.
RATHat Trojan Leverages Google Gemini to Infect and Control Android Devices
The banking trojan RATHat has begun using Google Gemini as an assistant to infect Android smartphones and maintain persistence. Researchers at Cleafy report that the malware first disguises itself as a legitimate application and tricks users into granting Accessibility permissions. Once inside, RATHat activates wireless debugging, connects via ADB, and deploys a separate Go-based service running with system-level privileges. Gemini helps the trojan interpret unfamiliar Android interfaces across different versions, languages, and manufacturer skins by analyzing UI structures and suggesting the correct taps. On the attacker side, the same model processes intercepted SMS messages, evaluates bank balances, and ranks compromised devices by financial value. Since April, Cleafy has observed nearly 100 deployments of the command-and-control infrastructure, pointing to a possible malware-as-a-service model. Removing the original APK is insufficient because the Go service survives independently until reboot and can reinstall the dropped payload.
Mimbrob Malware Uses Fake Dronner App to Target Russian Military and Industrial Firms
Researchers at F6 have identified a new malware campaign dubbed Mimbrob that leverages a fake drone-tracking application called Dronner. The lure promises data on heavy Baba Yaga drones and remote mining locations but instead deploys malicious payloads aimed primarily at Russian military personnel near the front line. The malware checks system language, keyboard layouts, and interface preferences, remaining dormant or terminating if Russian or certain CIS and Romanian languages are absent. Since April 2026 the same operators have conducted phishing campaigns against Russian industrial and IT companies using FBULoader disguised as a Yandex Browser update and the RAT-Go remote access trojan. The attackers register lookalike domains of legitimate Russian enterprises to deliver fake metrology notices and court documents. While espionage appears the most probable objective, researchers have not yet obtained the final payload and therefore refrain from definitive attribution.