The Android ecosystem is facing a dangerous evolution of RedHook, a banking trojan that has transitioned from simple spying to full-scale remote hijacking. This new variant manipulates built-in developer features to obtain elevated privileges, allowing attackers to silently drain victims' bank accounts.

Add AlexTech.ai asPreferred Source on Google

The Secret Weapon: Wireless ADB Abuse

The core of RedHook's strategy lies in the exploitation of Wireless ADB (Android Debug Bridge), a tool designed for developers to test apps without cables. According to an analysis by Group-IB, the malware uses a self-pairing technique via the loopback address 127.0.0.1, essentially connecting the phone to itself to simulate a developer's USB session.

To achieve this, RedHook integrates code from Shizuku, a well-known open-source tool used by enthusiasts to unlock elevated permissions without rooting the device. Once Wireless ADB is activated, RedHook gains shell-level access, granting it powers far beyond those of a standard application.

The Attack Chain and Total Control

The infection typically begins with social engineering: victims receive calls or messages impersonating government agencies or financial institutions, directing them to fake Google Play lookalike websites. There, they are tricked into sideloading a malicious APK.

Once installed, the trojan requests accessibility permissions. If granted, RedHook can:

  • Automatically enable Developer Options and wireless debugging.
  • Silently install or remove applications.
  • Stream the screen and capture keystrokes (keylogging).
  • Change secure settings to prevent its own removal.

A Concrete Risk for Modern Devices

This threat does not spare high-end hardware; reports highlight that owners of cutting-edge devices, such as the Pixel 10 Pro or Galaxy S26 Ultra, are vulnerable if they fall for phishing traps. The ability to operate without root makes RedHook particularly insidious, as it bypasses many traditional integrity-based protections.

In a landscape of increasing mobile security instability, where even browsers require frequent critical updates for memory flaws, the abuse of legitimate features like Wireless ADB marks a shift toward more sophisticated and stealthy attacks.