Android remote access tool abusing Accessibility Services
Malware Activity
Summary
Hide ▲
Show ▼
An unnamed Android remote access tool was found abusing Accessibility Services to take over devices, capture screenshots, steal credentials, and block removal. The malware’s always-on C2 connection lets operators push commands, updates, and fake in-app content, making account compromise and persistence harder to stop.
Related Happenings
RedHook Android malware abuses Wireless ADB for shell access
Malware Activity
H score26
First: 12.07.2026 17:27
Last: 12.07.2026 17:27
Sources 1
About this happening:
The RedHook Android malware now abuses Wireless ADB to obtain shell (UID 2000) privileges, expanding its control over infected devices. The change lets the malware ope...
RedHook Android malware abuses Wireless ADB for shell access
Malware ActivityAbout this happening: The RedHook Android malware now abuses Wireless ADB to obtain shell (UID 2000) privileges, expanding its control over infected devices. The change lets the malware ope...
RedWing Android spyware rented through Telegram
Malware Activity
H score21
First: 08.07.2026 18:30
Last: 08.07.2026 18:30
Sources 1
About this happening:
The RedWing Android spyware operation is being rented through Telegram, lowering the barrier for criminals to hijack phones and steal banking credentials. The malware...
RedWing Android spyware rented through Telegram
Malware ActivityAbout this happening: The RedWing Android spyware operation is being rented through Telegram, lowering the barrier for criminals to hijack phones and steal banking credentials. The malware...
RedWing Android bank-fraud malware rental service
Malware Activity
H score21
First: 07.07.2026 20:10
Last: 07.07.2026 20:10
Sources 1
About this happening:
The RedWing Android malware service is being rented on Telegram to steal banking logins, OTPs, and device control, raising fraud risk for banking and cryptocurre...
RedWing Android bank-fraud malware rental service
Malware ActivityAbout this happening: The RedWing Android malware service is being rented on Telegram to steal banking logins, OTPs, and device control, raising fraud risk for banking and cryptocurre...
Google Play Protect adds warnings and app disabling for compromised SDK abuse
Security Tool/Service
H score11
First: 03.07.2026 12:35
Last: 03.07.2026 12:35
Sources 1
About this happening:
Google Play Protect was updated in July 2026 to warn Android users automatically and disable apps tied to compromised SDKs, limiting abuse of consumer devices...
Google Play Protect adds warnings and app disabling for compromised SDK abuse
Security Tool/ServiceAbout this happening: Google Play Protect was updated in July 2026 to warn Android users automatically and disable apps tied to compromised SDKs, limiting abuse of consumer devices...
Rokarolla Android banking trojan activity
Malware Activity
H score26
First: 16.06.2026 16:15
Last: 16.06.2026 16:15
Sources 1
About this happening:
The Rokarolla Android banking trojan is expanding phone-level control on infected devices, letting attackers steal credentials, intercept authentication codes, and hide fr...
Rokarolla Android banking trojan activity
Malware ActivityAbout this happening: The Rokarolla Android banking trojan is expanding phone-level control on infected devices, letting attackers steal credentials, intercept authentication codes, and hide fr...
Timeline
-
30.01.2026 00:08 2 articles · 5mo ago
Android remote access tool abusing Accessibility Services
Initial DisclosureThe payload first requests Accessibility Services under the pretext of a security function, then uses that access to gain broad control over the device. That initial permission abuse enables screen capture, input manipulation, and resistance to removal.
Show sources
- Hugging Face abused to spread thousands of Android malware variants — www.bleepingcomputer.com — 30.01.2026 00:08
- Hugging Face abused to spread thousands of Android malware variants — www.bleepingcomputer.com — 30.01.2026 00:08