Home ยท Wiki ยท Entities & Threat Actors
type: entity ยท created: 2026-07-11 ยท updated: 2026-07-11 ยท tags: [rat, stealer, cybercrime-group] ยท confidence: high ยท affected_sectors: [finance, technology] ยท au_impact: false

RedWing MaaS

RedWing is a Malware-as-a-Service (MaaS) operation offering an Android banking trojan as a subscription service on Telegram for as low as $300/month. Identified by Zimperium zLabs as a variant of the Oblivion malware platform.

Capabilities

  • SMS / one-time passcode (OTP) interception
  • Overlay attacks on banking apps to steal credentials
  • Full phone takeover capabilities
  • Telegram bot-driven custom malicious app builds on demand

Distribution Model

  • Subscription: Rented at ~$300/month via Telegram
  • Custom builds: A Telegram bot builds custom malicious APKs on demand for subscribers
  • Low barrier to entry: Enables even low-skill criminals to deploy sophisticated banking trojans (raw/digests/Cyber-Digest-2026-07-07)

Technical Details

  • Android malware variant of the Oblivion platform
  • Overlay attacks target banking applications
  • SMS/OTP interception defeats SMS-based 2FA (raw/digests/Cyber-Digest-2026-07-09)

Related Pages

  • Scmbanker โ€” Another banking trojan using different infection vectors
  • Netnut Takedown โ€” Law enforcement action against cybercrime-enabling infrastructure