Affected Systems

Android devices targeted by RedWing malware, distributed as Malware-as-a-Service on Telegram. Variant of Oblivion MaaS. Primarily affects banking applications and users with compromised devices. No specific vendor products implicated; threat actor infrastructure-based.

Exploitation Status

Active exploitation confirmed. RedWing is being actively rented on Telegram for approximately $300/month, lowering barrier to entry for cybercriminals. Campaign is operational and targeting banking credentials and OTP codes in the wild.

Business Impact

Organizations with BYOD policies or mobile banking users face credential compromise risk. Stolen banking credentials and OTP interception enable account takeover and fraudulent transactions. Low technical barrier (MaaS model) increases threat actor pool. Mobile device management (MDM) and endpoint detection gaps may allow persistence. Financial services sector at elevated risk.

Urgency

🟡 Within a week

Recommended Actions

  • Deploy mobile threat defense (MTD) solutions on corporate and BYOD Android devices to detect RedWing and Oblivion variants
  • Block Telegram-based malware distribution channels at network perimeter and educate users on sideloading risks
  • Enforce Android Enterprise or Samsung Knox policies to restrict app installation from unknown sources
  • Monitor for anomalous SMS/OTP interception patterns and implement phishing-resistant MFA (FIDO2/passkeys) where possible
  • Review mobile banking app logs for credential stuffing attempts and correlate with device compromise indicators