The debugging function, built into every Android smartphone for developers, suddenly found itself in the hands of scammers and turned into a tool for completely capturing someone else's device.
We are talking about the RedHook Trojan, aimed at Android smartphones. The malware was first described in July 2025, but in the new version, it got the opportunity that Group-IB specialists had not met in mobile malware: independently turn on the ADB wireless debugging on the infected phone and, with its help, receive the rights of the system shell, root mine and without any action on the part of the victim.
According to Group-IB, the infection begins according to the classical scheme. Fraudsters call or write to the victim in the messenger, posing as employees of a bank or a state institution, and convince to install an application from a fake site, decorated under the official app store. The malware APK files themselves lie on quite legitimate sites – in GitHub repositories and Amazon S3 cloud storage, which reduces suspicions among protection systems.
After installation, the victim is persuaded to include access to special capabilities for the application, allegedly for the full operation of the service. It is this function that becomes the key to everything else. Having access to it, the Trojan automatically, without human intervention, goes to the phone settings, clicks on the build number seven times to open the developer menu, and turns on wireless debugging.
Usually, all these manipulations are hidden from the victim by a full screen overlay. Further, the malware launches its own ADB client on the device, which connects to the debug phone server directly through a local address, without the participation of a computer. At the heart of this mechanism is the code of the popular Shizuku tool, which is usually used by advanced Android users to expand the rights of applications without root access.
Having received system privileges, RedHook can secretly put and delete programs, change secure settings and give yourself permission without a single confirmation request. To stay in the system as long as possible, the Trojan uses several techniques at once: he simulates the active window on the screen, plays silent audio, keeps the processor from falling asleep and does not allow the system to complete its process with a lack of memory.
Two malware processes mutually restart each other when trying to stop them, and after rebooting the phone, an individual component automatically restores all privileges again. Stolen data and video stream from the screen are transmitted through a secure network connection to the servers of the attackers. If system rights have already been received, the malware is able to broadcast the screen directly bypassing a standard system request for screen recording resolution.
According to reports, the attacks are still concentrated in Southeast Asia, where infections were recorded in Vietnam, and later in Indonesia. For protection, it is recommended to install applications only from official stores, be wary of unknown sources, carefully check the requested permissions and especially wary of the request to include access to the special features of the device.
We are talking about the RedHook Trojan, aimed at Android smartphones. The malware was first described in July 2025, but in the new version, it got the opportunity that Group-IB specialists had not met in mobile malware: independently turn on the ADB wireless debugging on the infected phone and, with its help, receive the rights of the system shell, root mine and without any action on the part of the victim.
According to Group-IB, the infection begins according to the classical scheme. Fraudsters call or write to the victim in the messenger, posing as employees of a bank or a state institution, and convince to install an application from a fake site, decorated under the official app store. The malware APK files themselves lie on quite legitimate sites – in GitHub repositories and Amazon S3 cloud storage, which reduces suspicions among protection systems.
After installation, the victim is persuaded to include access to special capabilities for the application, allegedly for the full operation of the service. It is this function that becomes the key to everything else. Having access to it, the Trojan automatically, without human intervention, goes to the phone settings, clicks on the build number seven times to open the developer menu, and turns on wireless debugging.
Usually, all these manipulations are hidden from the victim by a full screen overlay. Further, the malware launches its own ADB client on the device, which connects to the debug phone server directly through a local address, without the participation of a computer. At the heart of this mechanism is the code of the popular Shizuku tool, which is usually used by advanced Android users to expand the rights of applications without root access.
Having received system privileges, RedHook can secretly put and delete programs, change secure settings and give yourself permission without a single confirmation request. To stay in the system as long as possible, the Trojan uses several techniques at once: he simulates the active window on the screen, plays silent audio, keeps the processor from falling asleep and does not allow the system to complete its process with a lack of memory.
Two malware processes mutually restart each other when trying to stop them, and after rebooting the phone, an individual component automatically restores all privileges again. Stolen data and video stream from the screen are transmitted through a secure network connection to the servers of the attackers. If system rights have already been received, the malware is able to broadcast the screen directly bypassing a standard system request for screen recording resolution.
According to reports, the attacks are still concentrated in Southeast Asia, where infections were recorded in Vietnam, and later in Indonesia. For protection, it is recommended to install applications only from official stores, be wary of unknown sources, carefully check the requested permissions and especially wary of the request to include access to the special features of the device.