RedHook Android malware can quietly hijack your phone
Cybersecurity researchers have identified an upgraded version of RedHook, an Android remote access trojan that exploits the operating system's Wireless Debugging feature to seize deep control of infected devices. Victims are typically tricked by scam callers posing as bank or government officials, who direct them to a fake Google Play page and persuade them to install an app and enable Accessibility permissions. Once granted, this access allows the malware to read the screen, simulate taps and gain shell-level privileges, giving attackers far greater control than a standard malicious app would normally achieve.
The malware was analysed by Group-IB, a global cybersecurity firm that investigates online fraud, which found that RedHook can run powerful system commands once it has obtained shell access via Wireless Debugging. The attack relies heavily on social engineering, with fraudsters using urgent, official-sounding phone calls to pressure victims into bypassing normal safeguards before the app requests its critical permissions.
- RedHook malware abuses Android's Wireless Debugging to hijack phones
- Scammers pose as officials to trick users into installing it
- Accessibility permission grants attackers deep, shell-level device control