Kuwait Press Memory Latest news
alraiTrending By | إعداد عبدالعليم الحجار|

"RedHook"... Malware Breaches Android Devices

"RedHook"... Malware Breaches Android Devices

Cybersecurity firm Group-IB has unveiled a newer and more dangerous version of the RedHook spyware, designed to target Android devices. This malware can now exploit the Wireless ADB debugging feature to gain deep control over a phone without needing a computer connection or even root access. According to Android Authority, this method represents a qualitative leap in hacking techniques aimed at Android devices.

Introduced for the first time with Android 11, this feature allows developers to remotely control their devices over a network without a USB cable. However, RedHook turns this legitimate development tool into an offensive weapon. After deceiving the victim, the malware leverages Accessibility permissions to automatically enable Developer Options and activate Wireless ADB by simulating user taps.

Once the pairing code displayed on the screen is extracted, the malicious software connects to the device’s ADB service via the internal communication interface, thereby obtaining shell-level execution privileges known as user ID 2000. These privileges are significantly higher than those typically granted to ordinary applications. Group-IB researchers clarified that the malware subsequently uses an open-source framework called Shizuku to run a specialized server, which grants it the ability to self-elevate permissions, execute system commands, and silently install or uninstall applications without any user notification.

To ensure it remains active for as long as possible, RedHook relies on an unusual mechanism dubbed by researchers as “mutual process emission,” where each service revives the other immediately upon being stopped. Additionally, it plays a silent sound in the background to raise the process priority and adjusts the internal memory management value to the lowest possible level to avoid being automatically killed when memory is low.

The malware initially spread among users in Vietnam before expanding to Indonesia. Attackers rely on social engineering tactics, impersonating support staff or government officials via text messages or phone calls, to convince victims to install malicious apps from fake websites mimicking the Google Play Store.

In this regard, experts recommend several preventive measures, including:

• Restricting app downloads exclusively to the official Google Play Store and keeping Play Protect enabled at all times.

• Exercising extreme caution when any request is made to grant Accessibility permissions, particularly from apps of unknown origin.

Although there is no technical vulnerability to patch in this case, researchers emphasize that the first line of defense remains user awareness, as the entire attack relies on deceiving the user rather than directly exploiting a technical flaw in the system.

Latest news Original source
Link copied ✓