A new Android malware operation called RedWing, identified by mobile security firm Zimperium's zLabs research team on July 7, 2026, is being offered as a ready-to-use banking fraud service on Telegram. The malware, which is a variant of the Oblivion family (previously documented renting for around $300 a month), enables phone takeover, credential theft, and one-time password capture, with overlay phishing pages built for more than 82 financial institutions.

The commoditization of mobile banking fraud through malware-as-a-service represents a significant threat to financial institutions and their customers. Low-skill attackers can now purchase sophisticated banking trojan capabilities without needing to develop malware themselves.

What Happened: RedWing Sold as Banking Fraud Service

Zimperium's zLabs team identified RedWing, a variant of the Oblivion Android malware family, being marketed on Telegram as a malware-as-a-service offering. The service provides a Telegram bot that automatically builds and obfuscates malicious APKs, with droppers that mimic the Google Play Store, Samsung's Galaxy Store, and Huawei's AppGallery, plus an "Onboarding Constructor" tool for crafting social-engineering prompts that trick victims into granting permissions.

The malware's capabilities include phone takeover, credential theft from banking applications, and OTP capture. Beyond SMS interception, RedWing can silently forward a victim's incoming calls to an attacker-controlled number using the USSD code *21*, letting attackers intercept the confirmation calls banks use to verify suspicious transactions. It also provides live VNC screen control, keylogging, covert camera and microphone recording, and can convert infected devices into botnet nodes for HTTP flood DDoS attacks. Zimperium suspects links to Russian-speaking threat actors, and notes the overlay targets skew heavily toward Russian financial institutions among the 82-plus targeted.

Key Details

RedWing is distributed as malware-as-a-service, meaning the operators sell access to the malware infrastructure rather than using it directly. This business model has become increasingly common in the cybercrime ecosystem, allowing specialized developers to profit from their technical skills while less technical criminals handle victim targeting.

The custom droppers used to distribute RedWing mimic popular app stores and legitimate applications. Many variants evade detection by antivirus products, at least initially, through obfuscation and frequent updates.

Pricing and Detection

RedWing's operators sell it with the packaging of a legitimate SaaS product: plans reportedly range from a free one-hour test to $200 a month billed in USDT cryptocurrency, with subscription tiers, referral discounts, setup guides and how-to videos included. Zimperium says its Mobile Threat Defense product detects RedWing using on-device, AI-driven behavioral analysis that flags malicious activity without relying on cloud lookups or matching known malware signatures, a distinction that matters because signature-based detection is exactly what MaaS operators design their frequent app rebuilds to evade.

Overlay phishing, the technique behind RedWing's 82-plus pre-built bank targets, works by detecting when a victim opens a specific legitimate banking app and instantly displaying a malicious screen on top of it that looks identical to the real login page. The victim believes they're entering their credentials into their actual bank's app, when in fact the malware is capturing everything they type before, in some cases, passing it through to the real app so the victim notices nothing wrong. Building a convincing overlay for a specific bank requires closely replicating that bank's exact visual design and login flow, which is precisely the kind of repetitive, template-driven work a malware-as-a-service operation can industrialize and sell pre-built, rather than requiring each customer to build overlays themselves.

The call-forwarding technique using USSD code *21* is a particularly effective evasion of a security measure many banks consider a strong safeguard. Unstructured Supplementary Service Data (USSD) codes are short, standardized commands that trigger network-level actions directly through the phone's carrier, in this case unconditional call forwarding, without requiring any app-level permission a user would need to explicitly grant. Because it operates below the application layer, this technique lets RedWing silently redirect a bank's verification phone call to an attacker-controlled number even on a device where the user might otherwise notice a suspicious app permission request, defeating a fraud-verification method banks specifically use because they assumed it was harder to intercept than an SMS-based code.

Why It Matters

Banking malware distributed as a service lowers the barrier to entry for financial fraud. Attackers who lack technical skills can rent sophisticated tools for a fraction of the development cost. This expands the pool of potential attackers and increases the volume of fraud attempts.

The targeting of OTP mechanisms is particularly concerning because many users and institutions rely on SMS or app-based codes as their primary 2nd factor. Malware that can intercept these codes effectively bypasses this protection.

Industry Context

Mobile banking has grown dramatically, and so has mobile banking malware. Android's open ecosystem makes it a frequent target, though iOS is not immune. Banking trojans have evolved from simple credential harvesters to sophisticated tools capable of real-time transaction manipulation.

Telegram has become a popular platform for cybercrime services due to its encryption, large group capabilities, and relative lack of content moderation compared to mainstream social platforms.

What It Means for Users and the Industry

Android users should avoid installing applications from sources other than the official Google Play Store. Even on Google Play, users should review app permissions and developer reputations carefully. Banking applications should be protected with hardware-based security keys rather than SMS-based 2-factor authentication where possible.

For financial institutions, the RedWing service is another indicator that mobile banking fraud is becoming more industrialized. Detection systems need to account for compromised devices, not just stolen credentials.

What Happens Next

Security researchers will continue tracking RedWing variants and distribution channels. Google will update Play Protect to detect known samples. Law enforcement may attempt to identify and disrupt the service operators.

Final Takeaway

RedWing illustrates how the malware-as-a-service model is making sophisticated mobile banking fraud accessible to a broader range of criminals. Users and institutions need defense strategies that account for compromised devices.

Key Points

  • A new Android malware operation called RedWing, identified by mobile security firm Zimperium's zLabs research team on July 7, 2026, is being offered as a ready-to-use banking fraud service on Telegram.
  • The malware, which is a variant of the Oblivion family (previously documented renting for around $300 a month), enables phone takeover, credential theft, and one-time password capture, with overlay phishing pages built for more than 82 financial institutions.
  • Even on Google Play, users should review app permissions and developer reputations carefully.

Malware-as-a-Service Business Models

RedWing's distribution through Telegram as malware-as-a-service illustrates the industrialization of cybercrime. Specialized developers create and maintain malware infrastructure, while less technical criminals rent access and handle victim targeting. This division of labor allows each party to focus on their strengths and increases the overall volume of attacks.

The Telegram platform has become popular for cybercrime services due to its encryption, large group capabilities, and relatively permissive content policies compared to mainstream social platforms. Law enforcement faces challenges in monitoring these channels, particularly when operators use encryption and anonymity techniques.

Zimperium has not confirmed RedWing's exact rental price, though the underlying Oblivion malware family it is based on was previously documented renting for around $300 a month; similar banking malware services typically charge hundreds to thousands of dollars per month depending on features and support. This pricing makes sophisticated capabilities accessible to criminals with limited technical skills.

FAQs

What is malware-as-a-service?
A business model where malware developers rent access to their tools and infrastructure to other criminals who conduct the actual attacks.
How does RedWing steal OTP codes?
RedWing sets itself as the default SMS handler to intercept 2FA codes, and can also silently forward a victim's incoming calls to an attacker-controlled number using the USSD code *21*, bypassing the confirmation calls banks use to verify suspicious transactions.
Can antivirus detect RedWing?
Many variants evade detection initially, though security vendors update signatures as samples become available. Users should avoid installing apps from unofficial sources.
Which malware family is RedWing based on?
RedWing is a variant of the Oblivion Android malware family, previously documented renting for around $300 a month, and it shares dropper and overlay techniques with Oblivion.
What other capabilities does RedWing have beyond OTP theft?
Zimperium documented live VNC screen control, keylogging, covert camera and microphone recording, data exfiltration (contacts, call logs, SMS, location, files), overlay phishing pages for more than 82 financial institutions, and the ability to convert infected devices into botnet nodes for DDoS attacks.
How can users protect against RedWing-style banking malware?
Install apps only from the official Google Play Store, review app permissions and developer reputation carefully, and use hardware-based security keys rather than SMS-based 2-factor authentication where possible.
AndroidMalwareBankingRedWingCybersecurity