JADEPUFFER: the first agentic ransomware
JADEPUFFER: the first agentic ransomware
External Attack Surface Management: reducing your external exposure
External Attack Surface Management: reducing your external exposure
Stay ahead of threats to your industry with real-time intelligence.
Stay ahead of threats to your industry with real-time intelligence.
Your executives are targets. Monitor your leadership's digital exposure.
Your executives are targets. Monitor your leadership's digital exposure.

Threat News
3 min read
RedWing: the Android banking malware that became a Telegram subscription

safe-e Intelligence Team
Cyber Threat Intelligence
A Malware-as-a-Service with plans, support and a bot that generates the APK on demand. Android bank fraud became an off-the-shelf product, and the same playbook already runs in Brazil.
Android bank fraud just became easy to buy. Researchers at Zimperium’s zLabs identified RedWing, a Malware-as-a-Service sold by subscription through a Telegram channel, complete with documentation, tutorial videos, a referral discount and a bot that generates the malicious APK on demand. In practice, an attacker with no technical skill assembles a banking trojan in minutes.
What RedWing does on the device
Once installed, it gives the operator near-total control: fake overlays on banking and cryptocurrency apps to steal credentials, SMS interception to capture 2FA codes, abuse of the Accessibility Service to pull PINs, card numbers and CVV straight off the screen, and call forwarding via the *21* code to defeat phone-based anti-fraud checks. Add to that real-time VNC, a keylogger, access to files, contacts and location, and remote activation of camera and microphone. Infected phones can become nodes in a botnet for DDoS attacks (Zimperium).
How the attack reaches the victim
It all starts with phishing over SMS or messaging apps, leading to a fake app-store page. RedWing’s builder mimics Google Play, Galaxy Store and Huawei AppGallery, with forged reviews, comments and download counters. After installation, a module called "Onboarding Constructor" disguises permission requests as routine setup steps. The three key permissions: disable battery optimization, become the default SMS app (essential for 2FA) and access notifications (Zimperium).
The shift: fraud sold as a subscription
RedWing is run as a professional-grade commercial product, with plans and support, all inside Telegram. Zimperium flags it as a variant or rebranding of the Oblivion RAT, sold from US$ 300 per month since February 2026 and with more than 7,500 devices already infected (Certo Software; ANY.RUN). The effect is clear: the barrier to entry disappears and mobile bank fraud becomes industrialized.
Why this matters for Brazil
The 82 targets observed so far are concentrated in the Russian financial sector, with no confirmed Brazilian victims. But the target list can change at any moment from the control panel, and the same pattern already operates here: in March 2026, zLabs itself revealed PixRevolution, a trojan built to attack Pix, with overlays of brands like Nubank, Itaú and Banco do Brasil and a real-time operator who swaps the Pix key at the moment the transfer is confirmed. Because Pix is instant and irreversible, the recovery window is minimal (Zimperium; Dark Reading).
What to do now
Block installation from outside the official stores (sideloading) on corporate and BYOD devices via MDM/UEM.
Alert on requests for the Accessibility Service and for "default SMS app".
Reduce SMS OTP: prioritize TOTP, FIDO2/WebAuthn or biometrics.
Adopt Mobile Threat Defense with on-device behavioral detection.
Monitor fakes of your brand in bogus app stores and on channels like Telegram.
Review phone-based anti-fraud, since the *21* call forwarding can neutralize it silently.
Conclusion
When crime becomes a subscription, volume and speed explode. RedWing shows that Android bank fraud is a few clicks away from any buyer, and PixRevolution proves the same playbook already runs in Brazil. Seeing your brand across distribution channels and defending the device at the source is what shortens the attacker’s window.
The full analysis, with indicators and risk reading, is in the Intelligence module of safe-e’s CTI platform.
Sources: Zimperium (zLabs) · Certo Software · iVerify · ANY.RUN · Dark Reading · The Hacker News · Infosecurity Magazine · Security Affairs.