A new Android malware operation called RedWing, identified by mobile security firm Zimperium's zLabs research team on July 7, 2026, is being offered as a ready-to-use banking fraud service on Telegram. The malware, which is a variant of the Oblivion family (previously documented renting for around $300 a month), enables phone takeover, credential theft, and one-time password capture, with overlay phishing pages built for more than 82 financial institutions.
The commoditization of mobile banking fraud through malware-as-a-service represents a significant threat to financial institutions and their customers. Low-skill attackers can now purchase sophisticated banking trojan capabilities without needing to develop malware themselves.
What Happened: RedWing Sold as Banking Fraud Service
Zimperium's zLabs team identified RedWing, a variant of the Oblivion Android malware family, being marketed on Telegram as a malware-as-a-service offering. The service provides a Telegram bot that automatically builds and obfuscates malicious APKs, with droppers that mimic the Google Play Store, Samsung's Galaxy Store, and Huawei's AppGallery, plus an "Onboarding Constructor" tool for crafting social-engineering prompts that trick victims into granting permissions.
The malware's capabilities include phone takeover, credential theft from banking applications, and OTP capture. Beyond SMS interception, RedWing can silently forward a victim's incoming calls to an attacker-controlled number using the USSD code *21*, letting attackers intercept the confirmation calls banks use to verify suspicious transactions. It also provides live VNC screen control, keylogging, covert camera and microphone recording, and can convert infected devices into botnet nodes for HTTP flood DDoS attacks. Zimperium suspects links to Russian-speaking threat actors, and notes the overlay targets skew heavily toward Russian financial institutions among the 82-plus targeted.
Key Details
RedWing is distributed as malware-as-a-service, meaning the operators sell access to the malware infrastructure rather than using it directly. This business model has become increasingly common in the cybercrime ecosystem, allowing specialized developers to profit from their technical skills while less technical criminals handle victim targeting.
The custom droppers used to distribute RedWing mimic popular app stores and legitimate applications. Many variants evade detection by antivirus products, at least initially, through obfuscation and frequent updates.
Pricing and Detection
RedWing's operators sell it with the packaging of a legitimate SaaS product: plans reportedly range from a free one-hour test to $200 a month billed in USDT cryptocurrency, with subscription tiers, referral discounts, setup guides and how-to videos included. Zimperium says its Mobile Threat Defense product detects RedWing using on-device, AI-driven behavioral analysis that flags malicious activity without relying on cloud lookups or matching known malware signatures, a distinction that matters because signature-based detection is exactly what MaaS operators design their frequent app rebuilds to evade.
Overlay phishing, the technique behind RedWing's 82-plus pre-built bank targets, works by detecting when a victim opens a specific legitimate banking app and instantly displaying a malicious screen on top of it that looks identical to the real login page. The victim believes they're entering their credentials into their actual bank's app, when in fact the malware is capturing everything they type before, in some cases, passing it through to the real app so the victim notices nothing wrong. Building a convincing overlay for a specific bank requires closely replicating that bank's exact visual design and login flow, which is precisely the kind of repetitive, template-driven work a malware-as-a-service operation can industrialize and sell pre-built, rather than requiring each customer to build overlays themselves.
The call-forwarding technique using USSD code *21* is a particularly effective evasion of a security measure many banks consider a strong safeguard. Unstructured Supplementary Service Data (USSD) codes are short, standardized commands that trigger network-level actions directly through the phone's carrier, in this case unconditional call forwarding, without requiring any app-level permission a user would need to explicitly grant. Because it operates below the application layer, this technique lets RedWing silently redirect a bank's verification phone call to an attacker-controlled number even on a device where the user might otherwise notice a suspicious app permission request, defeating a fraud-verification method banks specifically use because they assumed it was harder to intercept than an SMS-based code.
Why It Matters
Banking malware distributed as a service lowers the barrier to entry for financial fraud. Attackers who lack technical skills can rent sophisticated tools for a fraction of the development cost. This expands the pool of potential attackers and increases the volume of fraud attempts.
The targeting of OTP mechanisms is particularly concerning because many users and institutions rely on SMS or app-based codes as their primary 2nd factor. Malware that can intercept these codes effectively bypasses this protection.
Industry Context
Mobile banking has grown dramatically, and so has mobile banking malware. Android's open ecosystem makes it a frequent target, though iOS is not immune. Banking trojans have evolved from simple credential harvesters to sophisticated tools capable of real-time transaction manipulation.
Telegram has become a popular platform for cybercrime services due to its encryption, large group capabilities, and relative lack of content moderation compared to mainstream social platforms.
What It Means for Users and the Industry
Android users should avoid installing applications from sources other than the official Google Play Store. Even on Google Play, users should review app permissions and developer reputations carefully. Banking applications should be protected with hardware-based security keys rather than SMS-based 2-factor authentication where possible.
For financial institutions, the RedWing service is another indicator that mobile banking fraud is becoming more industrialized. Detection systems need to account for compromised devices, not just stolen credentials.
What Happens Next
Security researchers will continue tracking RedWing variants and distribution channels. Google will update Play Protect to detect known samples. Law enforcement may attempt to identify and disrupt the service operators.
Final Takeaway
RedWing illustrates how the malware-as-a-service model is making sophisticated mobile banking fraud accessible to a broader range of criminals. Users and institutions need defense strategies that account for compromised devices.
Key Points
- A new Android malware operation called RedWing, identified by mobile security firm Zimperium's zLabs research team on July 7, 2026, is being offered as a ready-to-use banking fraud service on Telegram.
- The malware, which is a variant of the Oblivion family (previously documented renting for around $300 a month), enables phone takeover, credential theft, and one-time password capture, with overlay phishing pages built for more than 82 financial institutions.
- Even on Google Play, users should review app permissions and developer reputations carefully.
Malware-as-a-Service Business Models
RedWing's distribution through Telegram as malware-as-a-service illustrates the industrialization of cybercrime. Specialized developers create and maintain malware infrastructure, while less technical criminals rent access and handle victim targeting. This division of labor allows each party to focus on their strengths and increases the overall volume of attacks.
The Telegram platform has become popular for cybercrime services due to its encryption, large group capabilities, and relatively permissive content policies compared to mainstream social platforms. Law enforcement faces challenges in monitoring these channels, particularly when operators use encryption and anonymity techniques.
Zimperium has not confirmed RedWing's exact rental price, though the underlying Oblivion malware family it is based on was previously documented renting for around $300 a month; similar banking malware services typically charge hundreds to thousands of dollars per month depending on features and support. This pricing makes sophisticated capabilities accessible to criminals with limited technical skills.
FAQs
Sources and Verification
This article was reviewed as part of CapisTech's editorial fact-checking process.



