RedHook: A New Android Banking Trojan Targeting Users In Vietnam
July 31, 2025, 7:52 p.m.
Description
A sophisticated Android banking trojan named RedHook has been discovered targeting Vietnamese users through spoofed government and financial websites. The malware uses WebSocket to communicate with its command-and-control server and supports over 30 remote commands, enabling complete control over compromised devices. RedHook combines phishing, RAT, and keylogging capabilities to exfiltrate credentials and conduct fraud. It abuses Android's MediaProjection API for screen capture and sends data to a live C2 server. The malware's low antivirus detection rate makes it a stealthy and active threat. Code artifacts suggest development by a Chinese-speaking threat actor or group. An exposed AWS S3 bucket revealed operational data dating back to November 2024, indicating a shift from previous scam campaigns to this advanced banking trojan.
Tags
Date
- Created: July 31, 2025, 7:23 p.m.
- Published: July 31, 2025, 7:23 p.m.
- Modified: July 31, 2025, 7:52 p.m.
Indicators
- ac8b2617d487e0d7719d506333c3ad4afbd014aedf75d684f072ae6f3c544dbc
- 8f4d41b11338583959d3d297cdb0c01214f84dfddc5dcdf25f8463f9c2d442d9
- ebc4bed126c380cb37e7936b9557e96d41a38989616855bb95c9107ab075daa3
- 41d09fb33d7696833c11c739a3b0929cd0bff70c29c1a8d00a9c2041c8d0b863
- f33ebe44521abb954ec6b1c18efc567fe940ae8b7b495a302885ecefceba535b
- ecc1ccc0f2e1b925834a63f0dc1f514c83329427f308575f417cc4799539398c
- 5427ce8b04fc8a09391c2f6eeed44230d256640e1e74f20a1c1f2fcdabea32df
- 8afbbc53e0b69e22ab444ba69718d543469efb4af2c65bcd27a47f12211a0a67
- 0ace439000c8c950330dd1694858f50b2800becc7154e137314ccbc5b1305f07
- skt9.iosgaxx423.xyz
- api9.iosgaxx423.xyz
- api5.jftxm.xyz
- adsocket.e13falsz.xyz
Attack Patterns
- RedHook
Additional Informations
- Finance
- Government