Connect with us

CyberSecurity

RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service

Published

on

RedWing Android malware

RedWing Android malware: A new Telegram rental for bank fraud

A fresh Android malware operation, dubbed RedWing, is being rented out on Telegram as a ready-made bank-fraud service. It lets even low-skill criminals take over a victim’s phone, steal their banking logins, and capture the one-time codes that protect their accounts.

Security researchers at Zimperium‘s zLabs unit, which discovered the operation, say it appears to be a new variant of Oblivion — a $300-a-month rent-a-malware tool that’s been circulating in underground forums since late 2023.

The rise of Malware-as-a-Service (MaaS) on messaging platforms like Telegram is lowering the barrier to entry for cybercrime. RedWing is the latest example, packaging sophisticated Android bank fraud into a subscription model anyone can buy.

How RedWing works: Remote access and OTP theft

RedWing is a Remote Access Trojan (RAT) specifically designed for Android devices. Once installed — often through malicious apps sideloaded from third-party stores or phishing links — it can:

  • Take over the victim’s screen in real time, allowing the attacker to see everything the user does.
  • Steal banking credentials by overlaying fake login pages on top of legitimate banking apps.
  • Intercept one-time passwords (OTPs) sent via SMS, defeating two-factor authentication.
  • Log keystrokes and capture screenshots, giving the attacker full visibility into the device.

The malware communicates with its command-and-control (C2) server over encrypted channels, making detection harder for traditional antivirus tools. Zimperium’s zLabs says RedWing targets over 100 banking apps globally, with a particular focus on European and Latin American financial institutions.

Oblivion connection: A $300-a-month malware family

Zimperium’s analysis reveals strong code similarities between RedWing and the Oblivion malware family. Oblivion, first documented in early 2024, was sold as a subscription service for $300 per month on Telegram and dark web forums. It offered similar capabilities — screen recording, keylogging, and SMS interception — but RedWing appears to be an upgraded version.

Key differences include:

  • Improved obfuscation to evade Google Play Protect and other security scanners.
  • New anti-analysis tricks, such as detecting if it’s running in an emulator or sandbox environment.
  • Expanded target list with more banking apps and cryptocurrency wallets.

The pricing for RedWing hasn’t been disclosed publicly, but Zimperium suspects it follows a similar subscription model. The Telegram channel advertising the service boasts features like “24/7 support” and “regular updates” — a sign that the operators are treating it as a professional business.

Telegram as a marketplace for cybercrime tools

Telegram has become a hub for cybercriminal activity, from selling stolen data to renting out malware. The platform’s encrypted messaging, large file sharing, and channel features make it ideal for underground marketplaces. RedWing’s operators use Telegram channels to advertise their product, provide customer support, and distribute updates.

This isn’t new. Researchers have documented dozens of MaaS operations on Telegram, including ransomware builders, DDoS-for-hire services, and phishing kits. What makes RedWing notable is its focus on Android bank fraud — a lucrative niche where even low-skill attackers can drain accounts if they have the right tools.

For victims, the consequences can be severe: emptied bank accounts, stolen identities, and months of financial recovery. For banks, it means constantly updating fraud detection systems to catch new variants of malware.

How to protect against RedWing and similar threats

Android users can take several steps to reduce their risk:

  • Only install apps from the Google Play Store. Sideloading apps from unknown sources is the primary infection vector for RedWing.
  • Review app permissions carefully. If a flashlight app asks for SMS access or screen overlay permissions, that’s a red flag.
  • Enable Google Play Protect and keep it updated. It won’t catch everything, but it blocks many known malware samples.
  • Use a reputable mobile security app that can detect malicious behavior in real time.
  • Never click on links in unsolicited SMS or email messages claiming to be from your bank. Instead, open your banking app directly.

For security teams, Zimperium recommends monitoring for traffic patterns associated with RedWing’s C2 servers and integrating mobile threat detection into their existing security stack.

The bigger picture: MaaS is here to stay

RedWing is just the latest in a growing wave of Malware-as-a-Service offerings. As long as there’s demand for easy-to-use cybercrime tools, developers will build them and market them on platforms like Telegram. The barrier to entry for digital bank fraud has never been lower.

For consumers, the takeaway is clear: treat your phone like a wallet, because that’s exactly what attackers see it as. And for the security industry, the challenge is keeping up with an ever-evolving threat landscape where a new variant can appear on Telegram overnight.

Zimperium’s full technical report on RedWing is available on their blog, with indicators of compromise (IOCs) for security teams to use. The company says it’s sharing its findings with Google and affected financial institutions to help mitigate the threat.

Continue Reading

CyberSecurity

Iran’s Nimbus Manticore Expands Arsenal With TWOSTROKE-Style Backdoor and SSH Tunneler

Published

on

Nimbus Manticore backdoor

New Malware, Same Old Game

Iran’s cyber espionage machine never sleeps. Group-IB researchers have just published a deep dive into Nimbus Manticore, an Islamic Revolutionary Guard Corps (IRGC)-affiliated hacking group that’s been quietly expanding its toolkit. The findings reveal a previously undocumented backdoor that borrows heavily from TWOSTROKE, plus a custom SSH tunneler designed to keep covert communications flowing.

This isn’t a flashy ransomware operation. It’s patient, methodical espionage — the kind that targets government networks and critical infrastructure, often for years without detection.

Meet the TWOSTROKE-Like Backdoor

Group-IB’s analysis describes the new backdoor as structurally similar to TWOSTROKE, a known malware family linked to Iranian cyber operations. But it’s not a carbon copy. The researchers found distinct modifications in how the malware handles command-and-control (C2) communications and data exfiltration.

The backdoor operates in phases. It first establishes persistence on the infected host, then reaches out to its C2 server using encrypted channels. Once connected, it can execute arbitrary commands, upload and download files, and even manipulate system processes. The TWOSTROKE-like design makes it harder for defenders to spot — it blends in with legitimate network traffic.

Key Capabilities

  • Encrypted C2 communications that mimic normal HTTPS traffic
  • Modular command execution for post-exploitation tasks
  • File exfiltration with built-in compression and chunking
  • Persistence mechanisms that survive system reboots

Group-IB says the code quality is high. This isn’t a rushed job. The malware includes error-handling routines and anti-analysis tricks that suggest experienced developers are behind it.

The SSH Tunneler: A Quiet Workhorse

Alongside the backdoor, Nimbus Manticore deployed a custom SSH tunneler. This tool is deceptively simple: it establishes a secure tunnel between the victim’s network and an external server controlled by the attackers. But that simplicity is what makes it dangerous.

Once the tunneler is in place, the attackers can route traffic through the compromised network as if they were sitting inside it. This allows them to reach internal systems that aren’t directly exposed to the internet — databases, admin panels, or other machines on the same LAN. For a group focused on espionage, that’s gold.

Who Exactly Is Nimbus Manticore?

Nimbus Manticore has been on Group-IB’s radar for a while. The researchers describe the group as one of the most active Iranian APT actors in 2026, with a focus on intelligence gathering rather than sabotage. Their targets have included government entities, telecommunications firms, and research institutions across the Middle East and beyond.

The group operates under the banner of the IRGC, Iran’s ideological military force. That affiliation gives them resources and cover, but it also makes their activities a matter of national security concern for countries on the receiving end.

Attribution and Overlaps

Group-IB’s report notes overlaps with other known Iranian threat actors, suggesting the groups share tools or even personnel. The TWOSTROKE-like backdoor, for instance, bears resemblance to code previously attributed to a different IRGC-linked cluster. This kind of tool-sharing is common in state-sponsored ecosystems — it’s cheaper than developing everything from scratch.

What This Means for Defenders

If you’re responsible for securing a network that might be in Nimbus Manticore’s crosshairs, the takeaway is straightforward: expect stealthy, persistent intrusions that prioritize data theft over disruption. The use of SSH tunneler means you can’t just watch the perimeter — you need to monitor internal traffic for anomalies.

Group-IB recommends several defensive measures:

  • Deploy endpoint detection and response (EDR) tools that can spot unusual process behavior
  • Monitor outbound connections for encrypted tunnels that don’t match known business applications
  • Segment networks to limit lateral movement if one machine is compromised
  • Patch vulnerabilities promptly — many initial access vectors exploit known flaws

This isn’t just another APT report. It’s a reminder that Iranian cyber operations continue to evolve, and the tools they use are getting more sophisticated. The TWOSTROKE-like backdoor and SSH tunneler are just the latest additions to an arsenal that shows no signs of shrinking.

For more on related threat activity, check out our analysis of Iranian APT groups targeting critical infrastructure and the broader state-sponsored cyber espionage landscape.

Continue Reading

CyberSecurity

FBI Disrupts China-Linked QTFY Hacking Infrastructure Used to Steal U.S. Data

Published

on

QTFY hacking platforms

FBI Disrupts China-Linked QTFY Hacking Platforms

The U.S. Department of Justice (DoJ) announced on Wednesday the disruption of two hacking platforms—QScan and QTRouter—operated by Chinese threat actors targeting critical infrastructure and sensitive networks across the United States. The operation marks a significant blow to a state-sponsored group known as QTFY, linked to Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司).

This isn’t just another takedown. The FBI, alongside international partners, seized domain names and infrastructure tied to the group’s operations, effectively cutting off a pipeline used to exfiltrate data from American organizations.

What Are QScan and QTRouter?

QScan served as a scanning tool, probing networks for vulnerabilities. QTRouter, meanwhile, acted as a relay—routing stolen data back to the attackers. Together, they formed a two-step assault: find the weakness, then exploit it.

Think of it as a burglar casing a house, then bringing a truck to haul away the goods. The DoJ’s action dismantled both the casing tools and the getaway vehicle.

Targeting Critical Infrastructure

The group didn’t go after random victims. Their focus was on critical infrastructure—energy grids, water systems, and healthcare networks. These are the systems that keep the country running, and a breach could have catastrophic consequences.

The FBI’s operation neutralized the threat before it could escalate into a full-blown crisis.

Who Is Behind QTFY?

Attribution points to a Chinese state-sponsored group operating under the name QTFY. The group is allegedly employed by Nanjing Xinjiuwei Network Technology Company, a firm based in China. This isn’t the first time Chinese actors have been accused of cyber espionage, but the scale and precision of this operation stand out.

The DoJ’s announcement didn’t name individual hackers, but the infrastructure takedown sends a clear message: the U.S. is watching, and it will act.

How the Disruption Worked

The FBI used court-authorized seizures to take control of domains and servers used by QScan and QTRouter. By redirecting traffic, they disrupted the group’s ability to communicate with their malware.

It’s a classic move in cyber operations—cut the head, and the body withers. The stolen data, if any, may now be unrecoverable for the attackers.

International Cooperation

While the DoJ didn’t specify all partners, U.S. agencies often work with allies like the UK’s National Cyber Security Centre or Europol. This collaborative approach makes it harder for threat actors to find safe havens.

For organizations worried about similar attacks, the takeaway is clear: patch vulnerabilities, monitor networks, and assume you’re a target.

What This Means for U.S. Organizations

If you’re running a business in the U.S., this disruption is good news. It removes a known threat, but it doesn’t eliminate the risk entirely. Chinese state-sponsored groups will adapt, and new tools will emerge.

The FBI’s action is a reminder that cyber defense is a shared responsibility. Government operations can only do so much; private sector vigilance is equally critical.

For more on protecting your organization, check out our guide on cybersecurity best practices for small businesses and the latest threat intelligence updates.

Looking Ahead

The QTFY disruption is a win, but it’s a battle in a larger war. As long as nation-states engage in cyber espionage, the U.S. will need to stay ahead.

For now, the FBI’s operation sends a strong signal: stealing data from American infrastructure has consequences.

Continue Reading

CyberSecurity

WhatsApp Upgrades Account Security: Multiple Passkeys, Stronger 2SV, and Smarter Caller ID

Published

on

WhatsApp account security

Passkeys Go Multi-Device

WhatsApp has quietly changed how you prove who you are when logging in. The Meta-owned messaging app announced Tuesday that it now supports multiple passkeys per account — a shift that matters more than it might sound.

Until now, you were stuck with a single passkey tied to one device. That was a headache for anyone juggling an iPhone and an Android phone, or switching devices regularly. Now you can register more than one passkey, so logging in from either platform works without friction.

The company says over 1 billion people already use a passkey to access their WhatsApp account. That’s a staggering number, and it shows how quickly the industry has moved away from traditional SMS-based authentication.

For those unfamiliar: a passkey replaces passwords with a cryptographic key stored on your device. You verify with your fingerprint, face scan, or PIN. No more typing in codes from text messages that can be intercepted or phished.

Two-Step Verification Grows Up

The bigger change is in two-step verification (2SV). Previously, WhatsApp locked your account behind a six-digit PIN. Simple, sure, but also predictable. Six digits offer only a million combinations — trivial for a determined attacker to brute-force.

That PIN is now being upgraded to a full password. You can make it longer, and it can include alphanumeric characters and special symbols. In other words, you can finally use something like Tr0ub4dor&3 instead of 123456.

This is a meaningful upgrade. A longer password with mixed characters exponentially increases the difficulty of guessing or cracking it. It also aligns WhatsApp with best practices that security professionals have been pushing for years.

One thing to note: this doesn’t replace your passkey. It’s an additional layer. If someone gets your phone, or you lose it, the 2SV password is still there as a backstop when you re-register your number.

Caller Context: A New Weapon Against Spam

The third feature is Android-only for now, and it’s aimed squarely at the scourge of spam calls.

When an Android user receives a call from someone not in their contacts, WhatsApp will now display additional information about the caller. You’ll see their country of origin and whether they share any WhatsApp groups with you. That’s a small detail that can tell you a lot before you pick up.

If a call comes from a random number in a different country, and you have no mutual groups, you know it’s probably not worth answering. But if you see that the caller is in a group with you — say, a neighborhood association or a work channel — it’s more likely to be legitimate.

“Scammers rely on urgency – now you can take a beat with some more info before answering,” WhatsApp said in its announcement.

That’s the right framing. Spam callers thrive on the moment of panic when the phone rings. A second of context can deflate that urgency entirely.

Building on Scam Alert

This update lands just a couple of weeks after WhatsApp rolled out WhatsApp Scam Alert, an optional feature that uses AI to flag suspicious messages from non-contacts. Together, the two features form a more coherent defense against social engineering.

Scam Alert works by analyzing incoming messages for patterns commonly used in scams — urgency, requests for money, suspicious links — and then warning you before you engage. Caller context extends that protection to voice calls.

It’s a sensible one-two punch. Messaging scams and voice scams often come from the same criminal networks. Blocking both channels makes the platform a harder target.

What This Means for Your Privacy

Some users might wonder whether caller context compromises privacy. Showing your country and mutual groups to a stranger who calls you — isn’t that a data leak?

Not quite. The information is shown only to the person receiving the call, and only when the caller is not in their contacts. It’s a one-way disclosure designed to help the recipient make an informed decision. Your phone number remains hidden unless you choose to reveal it.

WhatsApp has also been pushing WhatsApp username feature to bolster phone number privacy, so users can interact without exposing their digits at all. The two features complement each other: usernames hide your number, and caller context gives you more signal about who’s on the other end.

Security Beyond the Headlines

It’s worth remembering that WhatsApp’s security posture has had its ups and downs. Earlier this year, the company disclosed WhatsApp file spoofing and URL scheme vulnerabilities. Those were patched, but they serve as a reminder that no platform is bulletproof.

The new passkey and 2SV features are steps in the right direction, but they only work if you actually enable them. Passkeys are on by default in many cases, but the 2SV password — the upgrade from the old PIN — requires you to set it up.

Here’s what you should do right now:

  • Open WhatsApp Settings and check your passkey registration. If you use multiple devices, register a passkey on each one.
  • Update your two-step verification to a full password. Make it long, unique, and not reused anywhere else.
  • Turn on Scam Alert if you haven’t already. It’s optional, but it’s free protection.
  • If you’re on Android, pay attention to the new caller context screen. It could save you from a scam call.

Security is a process, not a product. WhatsApp’s latest update gives you better tools — but the final layer of protection is still you.

Continue Reading

Trending