Home Android New Android Banking Malware Impersonates Government Institutions to Target Users

New Android Banking Malware Impersonates Government Institutions to Target Users

0

A newly detected Android banking trojan, dubbed “RedHook,” is actively targeting users in Vietnam by masquerading as trusted government and financial institutions.

The sophisticated malware, which was discovered by Cyble Research and Intelligence Labs (CRIL), is being distributed via convincing phishing websites that impersonate the State Bank of Vietnam and other prominent organizations.

Phishing site distributing a malicious APK file

Users are deceived into downloading malicious APK files, often hosted on exposed AWS S3 buckets and delivered through spoofed domains, allowing the attackers to rapidly shift their infrastructure and adapt attack campaigns.

Chinese-Linked “RedHook” Trojan

RedHook is engineered for comprehensive device compromise, blending phishing techniques, keylogging, and remote access functionalities.

Once a victim installs the malware under the guise of a legitimate app, it immediately initiates a series of credential-harvesting steps starting with screens that impersonate official login pages of financial institutions.

The trojan persuades users to enable excessive permissions, including accessibility services and overlay rights, granting itself persistent, privileged control over targeted devices.

Notably, RedHook exploits Android’s MediaProjection API, enabling it to covertly capture and stream screen content to its command-and-control (C2) server.

This activity is managed via a persistent WebSocket connection which is uncommon in typical malware granting the threat actor live, interactive surveillance of compromised devices.

Further technical analysis reveals RedHook can execute a total of 34 different remote commands issued by its operators, from key injection, credential extraction, and forced installation or removal of apps, to screen locking and device reboots.

These operations enable extensive data theft and even direct fraud, as attackers can manipulate online banking sessions in real time.

Low Detection Rates

Artifacts found in the malicious app code and evidence from an open S3 bucket point to a Chinese-speaking threat actor or group.

Chinese-language strings were embedded throughout the logs and WebSocket interface screenshots, providing attribution clues.

The S3 bucket, in use since at least November 2024, held a trove of operational data including fake banking templates, screenshots of phishing stages, and references to ongoing Vietnamese scam campaigns.

Data exposed on open S3 bucket

A notable connection was established with the domain mailisa[.]me, previously linked to large-scale fraud in the Vietnamese cosmetic market, suggesting that this actor has evolved from simple scams to leveraging sophisticated malware for increased impact.

Despite its extensive capabilities, RedHook currently exhibits a low detection rate across mainstream antivirus engines, presenting a substantial risk particularly in Southeast Asia’s mobile-first financial ecosystem.

The malware’s phishing interfaces are sometimes reused or adapted from campaigns in other languages, indicating an iterative approach that could soon expand regional targeting.

According to the report, The campaign illustrates the evolving tactics of mobile threat actors, who now combine refined social engineering with advanced Android API abuse, allowing for stealthy, persistent, and multifaceted financial attacks.

Cybersecurity experts warn that the malware’s use of accessibility and overlay permissions enables it to circumvent both user suspicion and most existing security controls on the Android OS.

Security researchers strongly advise users to avoid sideloading any apps particularly financial tools outside of trusted platforms like Google Play, remain wary of all requests for high-level permissions, and regularly update both their operating systems and security software.

Institutions are urged to enhance their detection and rapid response frameworks, as well as share threat intelligence proactively to curb the spread of threats like RedHook.

Indicators of Compromise (IOC) Table

IndicatorTypeDescription
0ace439000c8c950330dd1694858f50b2800becc7154e137314ccbc5b1305f07SHA256RedHook sample
ebc4bed126c380cb37e7936b9557e96d41a38989616855bb95c9107ab075daa3SHA256RedHook sample
f33ebe44521abb954ec6b1c18efc567fe940ae8b7b495a302885ecefceba535bSHA256RedHook sample
41d09fb33d7696833c11c739a3b0929cd0bff70c29c1a8d00a9c2041c8d0b863SHA256RedHook sample
5427ce8b04fc8a09391c2f6eeed44230d256640e1e74f20a1c1f2fcdabea32dfSHA256RedHook sample
ac8b2617d487e0d7719d506333c3ad4afbd014aedf75d684f072ae6f3c544dbcSHA256RedHook sample
ecc1ccc0f2e1b925834a63f0dc1f514c83329427f308575f417cc4799539398cSHA256RedHook sample
8f4d41b11338583959d3d297cdb0c01214f84dfddc5dcdf25f8463f9c2d442d9SHA256RedHook sample
8afbbc53e0b69e22ab444ba69718d543469efb4af2c65bcd27a47f12211a0a67SHA256RedHook sample
adsocket[.]e13falsz.xyz, api9[.]iosgaxx423.xyz, skt9[.]iosgaxx423.xyz, api5[.]jftxm.xyzDomain/URLC&C, WebSocket URLs
dzcdo3hl3vrfl.cloudfront[.]net/Chinhphu.apk, nfe-bucketapk[.]s3.ap-southeast-1.amazonaws.com/SBV.apkURLDistribution URLs
sbvhn[.]com/URLPhishing URL

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Exit mobile version