Skip to content

Android Malware RedHook Exploits Wireless ADB for Device Takeover

In a nutshell: RedHook exploits Wireless ADB to gain full system control on Android devices, extending beyond typical banking trojan capabilities.

The Android malware RedHook has developed a new variant that exploits the developer feature Wireless ADB (Android Debug Bridge) to gain complete control over infected devices and drain bank accounts.

RedHook leverages Wireless ADB, a debugging function typically intended for developers, as an attack vector. This feature enables the malware to obtain system-level privileges and achieve an access level that goes beyond classic banking trojans.

For CISOs, this development is critical because Wireless ADB is neither enabled nor monitored by most users. Once the attacker activates this function on an infected device, they can control it completely – regardless of standard sandboxing and app permissions.

The exploitation of these developer tools demonstrates a shift towards lesser-known security gaps that are often not detected by conventional mobile device management systems. Organizations should review the extent to which their BYOD policies and MDM solutions control and prevent the activation of Wireless ADB.


Source: itwelt.at · Published July 16, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: