type: entity ยท created: 2026-07-11 ยท updated: 2026-07-11 ยท tags: [rat, stealer, cybercrime-group] ยท confidence: high ยท affected_sectors: [finance, technology] ยท au_impact: false
RedWing MaaS
RedWing is a Malware-as-a-Service (MaaS) operation offering an Android banking trojan as a subscription service on Telegram for as low as $300/month. Identified by Zimperium zLabs as a variant of the Oblivion malware platform.
Capabilities
- SMS / one-time passcode (OTP) interception
- Overlay attacks on banking apps to steal credentials
- Full phone takeover capabilities
- Telegram bot-driven custom malicious app builds on demand
Distribution Model
- Subscription: Rented at ~$300/month via Telegram
- Custom builds: A Telegram bot builds custom malicious APKs on demand for subscribers
- Low barrier to entry: Enables even low-skill criminals to deploy sophisticated banking trojans (raw/digests/Cyber-Digest-2026-07-07)
Technical Details
- Android malware variant of the Oblivion platform
- Overlay attacks target banking applications
- SMS/OTP interception defeats SMS-based 2FA (raw/digests/Cyber-Digest-2026-07-09)
Related Pages
- Scmbanker โ Another banking trojan using different infection vectors
- Netnut Takedown โ Law enforcement action against cybercrime-enabling infrastructure