Cybersecurity experts have warned Android users about a dangerous new version of the RedHook malware that can steal banking information without requiring root access. According to security firm Group-IB, the malware exploits Android’s Wireless ADB feature to gain deep control over infected devices, allowing hackers to access sensitive data with advanced shell-level permissions.
Once installed, RedHook can record keystrokes, capture screenshots, stream the phone’s screen, read SMS messages, access contacts, create fake verification screens, and remotely control the device through taps and swipes. These capabilities enable cybercriminals to steal banking credentials, passwords, one-time verification codes, and other personal information.
The malware is typically distributed through phishing campaigns, where attackers impersonate banks, government agencies, technical support teams, or other trusted organizations. Victims are directed to fake websites designed to look like the Google Play Store and tricked into downloading a malicious app outside the official store.
Top 10 Largest Companies in Pakistan by Market Capitalization (2026)
After installation, the app requests Accessibility permissions, claiming they are needed for normal operation. Once granted, the malware can enable Developer Options, activate Wireless Debugging, retrieve pairing codes, and connect to the device’s own ADB service, giving attackers extensive control without rooting the phone.
Users are strongly advised to download apps only from the official Google Play Store, avoid clicking suspicious links, never install APK files from unknown sources, and carefully review app permissions before granting access. Keeping Android devices updated and using trusted mobile security software can also help reduce the risk of infection.


