The bottom line: Malware RedHook leverages the native Wireless Android Debug Bridge (ADB) development tool on Android to gain full device control without exploits and compromise enterprise access – MFA alone does not protect against it.
A variant of Android malware RedHook is active in Southeast Asia and uses the Wireless Android Debug Bridge (ADB) instead of classical exploits to achieve full control over infected devices. The method works on all Android devices and poses a challenge for BYOD and mobile security strategies.
RedHook infects devices through social engineering, prompting users to activate access features. The malware then activates the Wireless Android Debug Bridge (ADB) in the background, a native development tool on every Android device. Through this channel, the malware gains shell-level access without exploiting a specific vulnerability. With control over input devices, session data, and display, the attacker can drain bank accounts and extract session tokens and login credentials.
Documented attack campaigns to date have focused on Vietnam and Indonesia. However, the underlying method is not geographically bound and works on any Android device regardless of origin region or banking market. Historically, successful mobile banking malware techniques have repeatedly spread to other regions.
For enterprises with BYOD (Bring Your Own Device) policies or managed private devices that have access to enterprise systems, RedHook poses a structural risk. Device compromise does not end with a single banking app – it captures all active session tokens and access rights valid on the device. Multi-factor authentication protects during login but becomes ineffective once the attacker controls the device.
RedHook’s persistence mechanisms – recurring processes, wake locks, and background activities – are designed to maximize dwell time in the system. The detection timeline determines the extent of damage. Many organizations detect compromises more slowly than attackers operate.
Protective measures require continuous verification of sessions and endpoints at each access request, not only at login. Enterprises that do not control their BYOD landscape or treat MFA as a final rather than initial security layer are already at a disadvantage.
Source: www.it-daily.net · Published 17 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.