A newly detected Android banking trojan, dubbed “RedHook,” is actively targeting users in Vietnam by masquerading as trusted government and financial institutions.
The sophisticated malware, which was discovered by Cyble Research and Intelligence Labs (CRIL), is being distributed via convincing phishing websites that impersonate the State Bank of Vietnam and other prominent organizations.
Users are deceived into downloading malicious APK files, often hosted on exposed AWS S3 buckets and delivered through spoofed domains, allowing the attackers to rapidly shift their infrastructure and adapt attack campaigns.
Chinese-Linked “RedHook” Trojan
RedHook is engineered for comprehensive device compromise, blending phishing techniques, keylogging, and remote access functionalities.
Once a victim installs the malware under the guise of a legitimate app, it immediately initiates a series of credential-harvesting steps starting with screens that impersonate official login pages of financial institutions.
The trojan persuades users to enable excessive permissions, including accessibility services and overlay rights, granting itself persistent, privileged control over targeted devices.
Notably, RedHook exploits Android’s MediaProjection API, enabling it to covertly capture and stream screen content to its command-and-control (C2) server.
This activity is managed via a persistent WebSocket connection which is uncommon in typical malware granting the threat actor live, interactive surveillance of compromised devices.
Further technical analysis reveals RedHook can execute a total of 34 different remote commands issued by its operators, from key injection, credential extraction, and forced installation or removal of apps, to screen locking and device reboots.
These operations enable extensive data theft and even direct fraud, as attackers can manipulate online banking sessions in real time.
Low Detection Rates
Artifacts found in the malicious app code and evidence from an open S3 bucket point to a Chinese-speaking threat actor or group.
Chinese-language strings were embedded throughout the logs and WebSocket interface screenshots, providing attribution clues.
The S3 bucket, in use since at least November 2024, held a trove of operational data including fake banking templates, screenshots of phishing stages, and references to ongoing Vietnamese scam campaigns.
A notable connection was established with the domain mailisa[.]me, previously linked to large-scale fraud in the Vietnamese cosmetic market, suggesting that this actor has evolved from simple scams to leveraging sophisticated malware for increased impact.
Despite its extensive capabilities, RedHook currently exhibits a low detection rate across mainstream antivirus engines, presenting a substantial risk particularly in Southeast Asia’s mobile-first financial ecosystem.
The malware’s phishing interfaces are sometimes reused or adapted from campaigns in other languages, indicating an iterative approach that could soon expand regional targeting.
According to the report, The campaign illustrates the evolving tactics of mobile threat actors, who now combine refined social engineering with advanced Android API abuse, allowing for stealthy, persistent, and multifaceted financial attacks.
Cybersecurity experts warn that the malware’s use of accessibility and overlay permissions enables it to circumvent both user suspicion and most existing security controls on the Android OS.
Security researchers strongly advise users to avoid sideloading any apps particularly financial tools outside of trusted platforms like Google Play, remain wary of all requests for high-level permissions, and regularly update both their operating systems and security software.
Institutions are urged to enhance their detection and rapid response frameworks, as well as share threat intelligence proactively to curb the spread of threats like RedHook.
Indicators of Compromise (IOC) Table
| Indicator | Type | Description |
|---|---|---|
| 0ace439000c8c950330dd1694858f50b2800becc7154e137314ccbc5b1305f07 | SHA256 | RedHook sample |
| ebc4bed126c380cb37e7936b9557e96d41a38989616855bb95c9107ab075daa3 | SHA256 | RedHook sample |
| f33ebe44521abb954ec6b1c18efc567fe940ae8b7b495a302885ecefceba535b | SHA256 | RedHook sample |
| 41d09fb33d7696833c11c739a3b0929cd0bff70c29c1a8d00a9c2041c8d0b863 | SHA256 | RedHook sample |
| 5427ce8b04fc8a09391c2f6eeed44230d256640e1e74f20a1c1f2fcdabea32df | SHA256 | RedHook sample |
| ac8b2617d487e0d7719d506333c3ad4afbd014aedf75d684f072ae6f3c544dbc | SHA256 | RedHook sample |
| ecc1ccc0f2e1b925834a63f0dc1f514c83329427f308575f417cc4799539398c | SHA256 | RedHook sample |
| 8f4d41b11338583959d3d297cdb0c01214f84dfddc5dcdf25f8463f9c2d442d9 | SHA256 | RedHook sample |
| 8afbbc53e0b69e22ab444ba69718d543469efb4af2c65bcd27a47f12211a0a67 | SHA256 | RedHook sample |
| adsocket[.]e13falsz.xyz, api9[.]iosgaxx423.xyz, skt9[.]iosgaxx423.xyz, api5[.]jftxm.xyz | Domain/URL | C&C, WebSocket URLs |
| dzcdo3hl3vrfl.cloudfront[.]net/Chinhphu.apk, nfe-bucketapk[.]s3.ap-southeast-1.amazonaws.com/SBV.apk | URL | Distribution URLs |
| sbvhn[.]com/ | URL | Phishing URL |
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates
