RedWing: The Rent-a-Fraud Kit Turning Android Phones Into Bank Robberies

A new Android malware sold on Telegram lets almost anyone hijack a victim's phone, steal banking logins and grab the codes meant to keep accounts safe.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: an unbranded Android-
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Zimperium's zLabs research team disclosed RedWing, a new Android banking malware being rented out on Telegram to would-be fraudsters.
  • RedWing appears to be a fresh variant of Oblivion, an earlier rent-a-malware kit that costs about $300 a month.
  • The malware takes remote control of infected Android phones and steals banking logins plus the one-time codes banks send to confirm payments.
  • Buyers don't need to write any code to run bank fraud at scale.

There's a new entry in the growing catalogue of Android banking malware, and this one comes with a price tag and a customer-service channel.

It's called RedWing. Researchers at Zimperium's zLabs, the mobile-security firm that first documented it, describe it as a ready-made fraud kit rented out on Telegram. Buyers don't need to know how to code. They pay, they point, they steal.

The operation was first reported by The Hacker News.

What does RedWing actually do to a phone?

It hands the attacker the keys. Once installed on an Android device, RedWing can watch what the victim types, capture their banking username and password, and grab the one-time passcodes, the short numeric codes a bank texts you to approve a payment, that are supposed to stop this exact kind of theft.

With those pieces in hand, a criminal can log into someone's mobile banking app remotely, approve a transfer and drain the account before the victim notices.

Zimperium says RedWing looks like a rebrand of an earlier kit called Oblivion, rented on underground channels for roughly $300 a month. This isn't a brand-new invention. It's a fresh coat of paint on a business model that already works. Zimperium's zLabs is the same team that catalogued 137 remote commands in the Rokarolla Android trojan we reported on 16 June, which targeted 217 banking and crypto apps using similar overlay tactics.

Why the Telegram angle matters

Malware-as-a-Service, often shortened to MaaS, is the criminal version of a software subscription. You pay a monthly fee, you get a working tool, and someone else handles the updates. Telegram has become the shop counter for these deals because it's easy to use and hard to police.

Android bank fraud is no longer the preserve of skilled developers. A person with a few hundred dollars and bad intentions can now run the kind of attack that once required a small team.

Compare it to the early days of phishing kits, where criminals sent fake emails to trick people into typing passwords into lookalike sites. Once those kits went on sale, phishing volume exploded. Mobile banking fraud is walking the same path.

Should you worry?

Yes, in a practical sense, though the countermeasures aren't complicated.

Install apps only from Google Play, and even then check the developer name before tapping install. Be suspicious of any app that asks for Accessibility Services permissions, the powerful controls Android uses to help people with disabilities and which malware abuses to read screens and tap buttons. If your banking app suddenly asks you to reinstall it, or a text message pushes you toward a link, stop and go to the bank's official app store page yourself.

If money moves out of your account without your say-so, call the bank immediately. Card networks and banks in most countries can freeze and often reverse fraudulent transfers if you flag them fast.

RedWing isn't a novel piece of engineering. It's a familiar Android overlay-and-accessibility attack, dressed up and repackaged for rental. That's precisely what makes it dangerous: the barrier to entry just got lower again.

© 2026 Threat Vectr