
RedWing: Android Spyware Offered as Malware-as-a-Service via Telegram by Russian Threat Actors
Breaking_NewsCyber_CrimeMalwareMobileSecurityAndroidCybercrimeHackinghacking_newsinformation_security_newsIT_Information_SecurityMaaSmalwaremalware-as-a-serviceRussian_threat_actorsRedWing_MalwareSecurity_AffairsSecurity_NewsTelegram
Zimperium’s zLabs team discovered RedWing, an Android spyware operation offered as a malware-as-a-service (MaaS) subscription via Telegram, with pricing reportedly lower than a coffee subscription. The malware is linked to Russian threat actors and shares origins with the Oblivion malware family. RedWing functions as a banking trojan and spyware tool, providing buyers with documentation, tutorial videos, and a referral system. The service enables cybercriminals to deploy Android-targeted surveillance and financial theft capabilities without advanced technical skills. No specific victim counts, technical indicators, or CVE IDs were disclosed in the report.