A new Android Trojan, RedWing, is spreading in Russia, disguised as applications and even ordinary video files. According to F6, from mid-July to mid-September alone, the number of compromised devices exceeded 10,000.

One of the discovered variants was distributed under the name "Accident Scene Video." In reality, the file had an .apk extension and installed an application. After launch, the user saw a fake Google Play page and an offer to update, and then the program requested access to Android's "Accessibility Services."

After granting this permission, RedWing gains almost complete control over the smartphone. The Trojan can intercept PIN codes, passwords, and graphic keys, read SMS, remotely unlock the device, launch applications and websites, and also view images from cameras and listen to the microphone.

There are also more unusual functions. RedWing can play sounds from the attackers' server on the infected phone and even open a pop-up chat from "Technical Support." The smartphone can also be used as a proxy server or participate in DDoS attacks.

Detecting and removing the Trojan after infection is difficult. It hides from the list of recently launched applications, maintains background operation using a silent audio track, and can automatically restart. When attempting to open an antivirus, file manager, or power-off menu, RedWing can redirect the user back to the home screen and display a fake update window.

F6 advises against installing APK files from messengers and unknown sources and to be especially cautious about applications that require access to "Accessibility Services." This permission can give the malicious program the ability to independently obtain other rights on the device.

Read more on the topic:

Comments

правилами