A new Android malware operation called RedWing is being offered as a ready-to-use banking fraud service on Telegram. The malware, which is a variant of the Oblivion family, enables phone takeover, credential theft, and one-time password capture for as little as a few hundred dollars per month.

The commoditization of mobile banking fraud through malware-as-a-service represents a significant threat to financial institutions and their customers. Low-skill attackers can now purchase sophisticated banking trojan capabilities without needing to develop malware themselves.

What Happened: RedWing Sold as Banking Fraud Service

Security researchers identified RedWing, a variant of the Oblivion Android malware family, being marketed on Telegram as a malware-as-a-service offering. The service provides custom droppers that mimic legitimate app stores, enabling attackers to distribute the malware through social engineering rather than technical exploitation.

The malware's capabilities include phone takeover, credential theft from banking applications, and OTP capture. These capabilities allow attackers to bypass 2-factor authentication that relies on SMS or app-based codes.

Key Details

RedWing is distributed as malware-as-a-service, meaning the operators sell access to the malware infrastructure rather than using it directly. This business model has become increasingly common in the cybercrime ecosystem, allowing specialized developers to profit from their technical skills while less technical criminals handle victim targeting.

The custom droppers used to distribute RedWing mimic popular app stores and legitimate applications. Many variants evade detection by antivirus products, at least initially, through obfuscation and frequent updates.

Why It Matters

Banking malware distributed as a service lowers the barrier to entry for financial fraud. Attackers who lack technical skills can rent sophisticated tools for a fraction of the development cost. This expands the pool of potential attackers and increases the volume of fraud attempts.

The targeting of OTP mechanisms is particularly concerning because many users and institutions rely on SMS or app-based codes as their primary 2nd factor. Malware that can intercept these codes effectively bypasses this protection.

Industry Context

Mobile banking has grown dramatically, and so has mobile banking malware. Android's open ecosystem makes it a frequent target, though iOS is not immune. Banking trojans have evolved from simple credential harvesters to sophisticated tools capable of real-time transaction manipulation.

Telegram has become a popular platform for cybercrime services due to its encryption, large group capabilities, and relative lack of content moderation compared to mainstream social platforms.

What It Means for Users and the Industry

Android users should avoid installing applications from sources other than the official Google Play Store. Even on Google Play, users should review app permissions and developer reputations carefully. Banking applications should be protected with hardware-based security keys rather than SMS-based 2-factor authentication where possible.

For financial institutions, the RedWing service is another indicator that mobile banking fraud is becoming more industrialized. Detection systems need to account for compromised devices, not just stolen credentials.

What Happens Next

Security researchers will continue tracking RedWing variants and distribution channels. Google will update Play Protect to detect known samples. Law enforcement may attempt to identify and disrupt the service operators.

Final Takeaway

RedWing illustrates how the malware-as-a-service model is making sophisticated mobile banking fraud accessible to a broader range of criminals. Users and institutions need defense strategies that account for compromised devices.

Malware-as-a-Service Business Models

RedWing's distribution through Telegram as malware-as-a-service illustrates the industrialization of cybercrime. Specialized developers create and maintain malware infrastructure, while less technical criminals rent access and handle victim targeting. This division of labor allows each party to focus on their strengths and increases the overall volume of attacks.

The Telegram platform has become popular for cybercrime services due to its encryption, large group capabilities, and relatively permissive content policies compared to mainstream social platforms. Law enforcement faces challenges in monitoring these channels, particularly when operators use encryption and anonymity techniques.

The pricing for RedWing access has not been publicly disclosed, but similar banking malware services typically charge hundreds to thousands of dollars per month depending on features and support. This pricing makes sophisticated capabilities accessible to criminals with limited technical skills.

FAQs

What is malware-as-a-service?
A business model where malware developers rent access to their tools and infrastructure to other criminals who conduct the actual attacks.
How does RedWing steal OTP codes?
RedWing uses phone takeover capabilities to intercept SMS messages and capture codes generated by authentication apps on compromised devices.
Can antivirus detect RedWing?
Many variants evade detection initially, though security vendors update signatures as samples become available. Users should avoid installing apps from unofficial sources.
Which malware family is RedWing based on?
RedWing is a variant of the Oblivion Android malware family, adapted and sold as a ready-to-use banking fraud service on Telegram.
How much does RedWing cost to rent?
Reports indicate access is available for as little as a few hundred dollars per month, though pricing for malware-as-a-service typically varies by features and support level.
How can users protect against RedWing-style banking malware?
Install apps only from the official Google Play Store, review app permissions and developer reputation carefully, and use hardware-based security keys rather than SMS-based 2-factor authentication where possible.

Sources and Verification

  1. CybersecurityHunter, July 2026

This article was reviewed as part of CapisTech's editorial fact-checking process.

AndroidMalwareBankingRedWingCybersecurity