Back to articles

Tag archive

#mobilesecurity

R
Jul 13, 2026

RedHook Android Malware Uses Wireless ADB for Shell Access

A new variant of the RedHook Android banking malware is actively targeting users of Android 11 and later. This updated version has a dangerous new capability: it abuses the Wireless Android Debug Bridge (ADB) feature to gain persistent shell access on an infected device. The attack begins with the user being tricked into installing a malicious APK. The malware then uses Accessibility Services permissions to enable Developer Options and wireless debugging autonomously. By pairing with itself over the local network, it can execute shell commands to steal data, control banking apps, and maintain persistence, making it extremely difficult to remove.

Jul 13, 20264 min read0 reactions0 comments