Zimperium uncovers Malware-as-a-Service platform

Zimperium uncovers Malware-as-a-Service platform

Share this content

Facebook
Twitter
LinkedIn

Zimperium has announced new research from zLabs detailing RedWing, a sophisticated Android Malware-as-a-Service (MaaS) platform.

The platform enables cybercriminals to deploy highly customizable mobile malware through a commercial subscription model.

Marketed through Telegram and distributed through mobile-targeted phishing (mishing) campaigns, RedWing combines advanced remote access, credential theft, surveillance and banking fraud capabilities into a turnkey platform that significantly lowers the barrier to launching sophisticated mobile attacks.

Unlike traditional Android malware operated by a single threat actor, RedWing provides subscribers with malware builders, phishing infrastructure, customizable payloads and remote administration tools, allowing attackers with limited technical expertise to deploy advanced mobile campaigns at scale.

Malware-as-a-Service

“Malware-as-a-Service has fundamentally changed the economics of cybercrime by making sophisticated mobile attack capabilities commercially available,” said Kern Smith, Vice President of Global Solutions, Zimperium.

“RedWing demonstrates how today’s threat actors can rent a complete attack platform capable of full device compromise, real-time surveillance and enterprise credential theft, including the ability to intercept or bypass multi-factor authentication, all with little technical expertise.

“Organizations can no longer afford to treat mobile as a secondary risk.

“It has become one of the most vulnerable enterprise attack surfaces, with every compromised device representing a potential entry point into the corporate environment.”

According to the zLabs research, RedWing allows attackers to:

– Gain full remote control of infected Android devices through live screen streaming and virtual device interaction

– Steal banking and cryptocurrency credentials using phishing overlays, SMS interception and multi-factor authentication bypass techniques

– Exfiltrate sensitive data, including contacts, messages, files, photos and device information

– Abuse legitimate Android services to maintain persistence, evade detection and support additional malicious activities, including DDoS attacks

Zimperium says its Mobile Threat Defense (MTD) detects RedWing using on-device AI-Empowered behavioral detection that identifies malicious activity without relying on cloud lookups or known malware signatures.

Combined with Mobile Application Protection Suite (MAPS), including Web Content Filtering and fraud detection capabilities, organizations can help prevent phishing, credential theft and device compromise before sensitive data is exposed, the company adds.