RedWing Android Malware‑as‑a‑Service Rents Out Bank‑Fraud Capabilities via Telegram
What Happened — A new Android banking‑trojan called RedWing is being offered on Telegram as a “rent‑a‑malware” service. For a subscription fee (≈ $300 / month) low‑skill criminals can obtain a package that hijacks a victim’s phone, harvests banking credentials, and captures one‑time passcodes (OTPs) used for transaction authentication.
Why It Matters for Compliance & Audit Readiness
- The scenario maps directly to SOC 2 CC6.1 (Logical Access) and CC6.2 (User Authentication) – controls designed to prevent unauthorized credential use and to ensure robust MFA handling.
- Continuous evidence of access‑control policies, MFA enforcement, and security‑awareness training becomes critical evidence in an audit when mobile‑banking threats like RedWing are active.
Who Is Affected — Financial services, fintech apps, and any organization that relies on mobile banking authentication (banks, credit unions, payment processors).
Recommended Actions
- Review and tighten mobile‑device access policies; enforce device‑level encryption and remote‑wipe capabilities.
- Validate MFA implementations can detect and block OTP‑capture techniques; log and monitor anomalous login patterns.
- Expand security‑awareness training to cover mobile phishing and malware‑installation vectors.
Technical Notes — RedWing appears to be a variant of the “Oblivion” Android banking trojan. It is distributed via Telegram channels, operates as a background service, intercepts SMS/notification OTPs, and forwards harvested credentials to the attacker’s C2. Source: The Hacker News