Bottom line: RedHook malware exploits the little-known Wireless ADB interface as an entry point for complete device compromise and data theft.
An Android malware called RedHook exploits Wireless ADB (Android Debug Bridge), a developer feature, to fully take over devices and plunder bank accounts. The attack enables threat actors an access level that far exceeds classic banking trojans.
The RedHook malware represents a new variant that exploits a developer feature that is virtually unknown to end users: Wireless ADB (Android Debug Bridge). This is an interface normally intended for app development and debugging.
By exploiting Wireless ADB, RedHook achieves a level of access to infected devices that typical banking trojans do not offer. The malware can gain full control over the device “silently” without the user noticing. This enables not only siphoning of bank accounts, but in principle also access to all other sensitive data and functions on the device.
For CISOs and security professionals, this is relevant because exploiting developer tools represents a new attack vector that is often not explicitly considered in conventional security concepts. The fact that these functions are unknown to users increases the risk of successful infection, as infected devices do not stand out through visible symptoms.
Source: itwelt.at · Published 16 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.