{"id":5064,"date":"2025-07-30T00:11:25","date_gmt":"2025-07-30T00:11:25","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=5064"},"modified":"2025-07-30T00:11:25","modified_gmt":"2025-07-30T00:11:25","slug":"android-banking-malware-masquerades-as-authorities-businesses-to-assault-customers","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=5064","title":{"rendered":"Android Banking Malware Masquerades as Authorities Businesses to Assault Customers"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>Cyble Analysis and Intelligence Labs (CRIL) has uncovered a complicated Android banking trojan dubbed RedHook, which disguises itself as reliable purposes from Vietnamese authorities and monetary establishments to deceive customers.<\/p>\n<p>This malware, first noticed within the wild round January 2025, exploits phishing web sites mimicking entities just like the State Financial institution of Vietnam, Sacombank, Central Energy Company, Visitors Police of Vietnam, and even the Authorities of Vietnam. <\/p>\n<p>Distributed by way of misleading domains reminiscent of sbvhn[.]com and hosted on AWS S3 buckets, RedHook methods customers into downloading malicious APKs that seem as official banking apps. <\/p>\n<h2 class=\"wp-block-heading\" id=\"discovery-of-redhook-trojan-targeting-vietnamese-f\"><strong>Discovery of RedHook Trojan <\/strong><\/h2>\n<p>As soon as put in, it prompts victims to allow accessibility providers and overlay permissions, granting it in depth management over the gadget. <\/p>\n<p>This mixture of permissions permits the trojan to observe consumer actions silently, overlay pretend interfaces, and bypass safety protocols, making it a potent device for credential theft and monetary fraud.<\/p>\n<p>RedHook\u2019s capabilities lengthen past fundamental phishing, incorporating distant entry trojan (RAT) functionalities, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/dcrat-targets-windows-systems\/\" target=\"_blank\" rel=\"noreferrer noopener\">keylogging<\/a>, and display screen seize by way of Android\u2019s MediaProjection API. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi_qmTNraQ6kv_oiwH4w-88XkQIbiqblt3OCTd6jObup4GEGSMjeMW3Dz5J0bXOiJnfmQTexI1WjyMCdVH9OdTxo8JhxKY8qSt40Tefe-uPbaw0lSABiT4B6ma7rDAoNLmHXzlld9n19Hm7WY6R5Uu4f7EVpO99JpPraKgVqUnsTsxY9iCYwwsXcqE_cYs\/s16000\/Phishing%20site%20distributing%20a%20malicious%20APK%20file.webp\" alt=\"Android Banking Malware\"\/><figcaption class=\"wp-element-caption\"><em>Phishing website distributing a malicious APK file<\/em><\/figcaption><\/figure>\n<\/div>\n<p>It establishes a persistent WebSocket connection to command-and-control (C2) servers like api9[.]iosgaxx423.xyz and skt9[.]iosgaxx423.xyz, enabling real-time communication and execution of over 30 instructions. <\/p>\n<p>These instructions vary from accumulating gadget data, SMS messages, and contacts to performing gestures like swipes, clicks, and textual content enter, in addition to putting in or uninstalling apps, capturing screenshots, and even rebooting the gadget. <\/p>\n<p>The malware\u2019s phishing workflow is meticulously designed: it begins with pretend identification verification prompts requiring uploads of citizen ID images, adopted by requests for banking particulars, passwords, and two-step verification codes. <\/p>\n<p>Keylogs, tagged with software package deal names and energetic class particulars, are exfiltrated to the C2, whereas steady display screen streaming by way of JPEG pictures permits risk actors to remotely work together with the gadget. <\/p>\n<p>Code artifacts, together with Chinese language-language strings in logs and uncovered screenshots from an open <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/aws-cdk-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">AWS S3 bucket<\/a> energetic since November 2024, level to a Chinese language-speaking developer or group behind RedHook. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjHnCWbJwBkBpAh-xss2gDVMg5EkZPurzdcLoDeCpAUxDBQdpnf1_lZBH2Fdb9KATFGh_bFZJlJnrWpeOxI8hZnhH5DAUfSgBaYeI-M4u7za59DTyN-_gSyaknLv2UA5msWplc2tEMxoUESZ8k_iDzTFVtf6a9bRq_Az7tQpm9sh49_mX0IXB2baNkvK2k\/s16000\/Data%20exposed%20on%20open%20S3%20bucket.webp\" alt=\"Android Banking Malware\"\/><figcaption class=\"wp-element-caption\"><em>Information uncovered on open S3 bucket<\/em><\/figcaption><\/figure>\n<\/div>\n<p>This bucket <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/cyble.com\/blog\/redhook-new-android-banking-targeting-in-vietnam\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">revealed<\/a> operational information like pretend templates, phishing interfaces, and proof linking to prior scams by way of the area mailisa[.]me, indicating an evolution from social engineering fraud to superior malware-driven assaults.<\/p>\n<h2 class=\"wp-block-heading\" id=\"stealthy-threat-with-low-detection-and-broader-imp\"><strong>Broader Implications<\/strong><\/h2>\n<p>Regardless of its superior options, RedHook maintains low detection charges on platforms like VirusTotal, underscoring its stealthy nature and the challenges in cellular risk landscapes. Evaluation exhibits it has contaminated over 500 units, with consumer IDs incrementing sequentially upon compromise. <\/p>\n<p>The trojan abuses reliable APIs for protection evasion, reminiscent of masquerading as trusted apps and injecting inputs to imitate consumer interactions, aligning with MITRE ATT&amp;CK methods like Phishing (T1660), Enter Injection (T1516), and Display screen Seize (T1513). <\/p>\n<p>It collects protected information, together with SMS (T1636.004) and contacts (T1636.003), exfiltrating by way of HTTP-based C2 channels (T1437.001). This allows systematic harvesting of delicate data for fraudulent transactions, typically with out sufferer consciousness.<\/p>\n<p>The emergence of RedHook highlights the escalating sophistication of Android banking trojans in high-risk areas like Vietnam, mixing phishing, RAT, and keylogging for complete gadget management. <\/p>\n<p>Cybersecurity specialists suggest downloading apps solely from official sources, scrutinizing permission requests, enabling two-factor authentication, and utilizing cellular safety options with real-time scanning. <\/p>\n<p>Retaining units up to date with safety patches is essential to mitigate vulnerabilities. Proactive risk intelligence, together with monitoring darkish internet actions, is important for early detection and response to such evolving cyber threats.<\/p>\n<h2 class=\"wp-block-heading\" id=\"indicators-of-compromise-iocs\"><strong>Indicators of Compromise (IOCs)<\/strong><\/h2>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Indicators<\/th>\n<th>Indicator Sort<\/th>\n<th>Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>0ace439000c8c950330dd1694858f50b2800becc7154e137314ccbc5b1305f07<\/td>\n<td>SHA256<\/td>\n<td>RedHook<\/td>\n<\/tr>\n<tr>\n<td>ebc4bed126c380cb37e7936b9557e96d41a38989616855bb95c9107ab075daa3<\/td>\n<td>SHA256<\/td>\n<td>RedHook<\/td>\n<\/tr>\n<tr>\n<td>f33ebe44521abb954ec6b1c18efc567fe940ae8b7b495a302885ecefceba535b<\/td>\n<td>SHA256<\/td>\n<td>RedHook<\/td>\n<\/tr>\n<tr>\n<td>adsocket[.]e13falsz.xyz<\/td>\n<td>URL<\/td>\n<td>C&amp;C server<\/td>\n<\/tr>\n<tr>\n<td>api9[.]iosgaxx423.xyz<\/td>\n<td>URL<\/td>\n<td>C&amp;C server<\/td>\n<\/tr>\n<tr>\n<td>skt9[.]iosgaxx423.xyz<\/td>\n<td>Area<\/td>\n<td>WebSocket URLs<\/td>\n<\/tr>\n<tr>\n<td>api5[.]jftxm.xyz<\/td>\n<td>Area<\/td>\n<td>WebSocket URLs<\/td>\n<\/tr>\n<tr>\n<td>dzcdo3hl3vrfl.cloudfront[.]internet\/Chinhphu.apk<\/td>\n<td>URL<\/td>\n<td>Purple Hook<\/td>\n<\/tr>\n<tr>\n<td>nfe-bucketapk[.]s3.ap-southeast-1.amazonaws.com\/SBV.apk<\/td>\n<td>URL<\/td>\n<td>Distribution URL<\/td>\n<\/tr>\n<tr>\n<td>sbvhn[.]com\/<\/td>\n<td>URL<\/td>\n<td>Phishing URL<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(135deg,rgb(238,238,238) 100%,rgb(169,184,195) 100%)\"><strong><strong><code><strong>Discover this Information Attention-grabbing! Observe us on\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.google.com\/publications\/CAAqKAgKIiJDQklTRXdnTWFnOEtEV2RpYUdGamEyVnljeTVqYjIwb0FBUAE?hl=en-IN&amp;gl=IN&amp;ceid=IN%3Aen\" target=\"_blank\" rel=\"noreferrer noopener\">Google Information<\/a>,\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>, &amp;\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/The_Cyber_News\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get Instantaneous Updates<\/strong>!<\/code><\/strong><\/strong><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Cyble Analysis and Intelligence Labs (CRIL) has uncovered a complicated Android banking trojan dubbed RedHook, which disguises itself as reliable purposes from Vietnamese authorities and monetary establishments to deceive customers. This malware, first noticed within the wild round January 2025, exploits phishing web sites mimicking entities just like the State Financial institution of Vietnam, Sacombank, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":5066,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[4367,797,717,4365,2789,216,4366,342],"class_list":["post-5064","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-agencies","tag-android","tag-attack","tag-banking","tag-government","tag-malware","tag-masquerades","tag-users"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/5064","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5064"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/5064\/revisions"}],"predecessor-version":[{"id":5065,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/5064\/revisions\/5065"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/5066"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5064"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5064"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5064"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-21 12:22:14 UTC -->