Sunday, October 11, 2026

RedHook Abuses Accessibility Service to Enable Developer Options and Wireless Debugging

RedHook, an Android Remote Access Trojan (RAT) first profiled in July 2025, has resurfaced with a markedly more dangerous capability: autonomous abuse of Android’s ADB Wireless Debugging to acquire shell-level privileges (uid 2000).

While its baseline toolkit screen streaming, keylogging, Accessibility-driven UI manipulation and credential theft remains intact, the latest RedHook builds demonstrate a deliberate move toward privilege escalation and resilient persistence by repurposing legitimate developer tooling and open-source frameworks.

At the heart of this escalation is RedHook’s use of Accessibility permissions to programmatically enable Developer Options and toggle Wireless Debugging.

The trojan simulates the exact UI interactions a user would perform tapping the build number multiple times, navigating Developer Options, and initiating Wireless Debugging pairing while running in the background behind a full-screen overlay.

This stepwise automation removes the need for a physical host or user awareness and positions Wireless Debugging as an on-device gateway to elevated capabilities.

RedHook embeds an ADB client and leverages the Shizuku model to run a privileged server process under shell uid 2000. Shizuku’s approach allowing an app to connect locally to the device’s ADB daemon over loopback has legitimate uses for enthusiasts and developers.

Once the shell-level server is active, the malware can grant itself runtime permissions, write into Settings.Secure (including WRITE_SECURE_SETTINGS), execute arbitrary shell commands, install or uninstall apps silently, and capture low-level touch events all without additional user prompts.

Distribution remains social-engineering driven. Operators distribute malicious APKs via spoofed government and financial sites and rely on voice or messaging-based persuasion to convince victims to install.

Threat Intelligence Portal (Source : GroupIB).
Threat Intelligence Portal (Source : GroupIB).

GroupIB Researchers said that, RedHook repurposes that pattern to spawn a privileged server (observed as libmx.so), expose Binder IPC interfaces, and execute protected system APIs.

RedHook Abuses Accessibility

Notably, payload hosting uses reputable cloud and development infrastructures Amazon S3 and GitHub among them to improve delivery reliability and avoid immediate takedown.

Recent telemetry shows an expansion of targeting from Vietnam into Indonesia, signaling a broader Southeast Asian campaign footprint.

RedHook phishing UI impersonating a vietnamese government authority's identity (Source : GroupIB).
RedHook phishing UI impersonating a vietnamese government authority’s identity (Source : GroupIB).

RedHook’s persistence stack combines several advanced techniques to survive reboots and process kills.

The malware uses a one-pixel activity to maintain foreground status while the screen is off, plays silent audio in a MediaSession to elevate process priority, holds WakeLocks to prevent suspension, and adjusts its process oom_score_adj to -1000 to make itself the last candidate for termination.

A two-process mutual resurrection mechanism cross-process binding with BIND_AUTO_CREATE and periodic alarms ensures services restart if terminated.

On BOOT_COMPLETED the app re-enables Wireless ADB, reloads ADB keys, and reestablishes the privileged helper to restore full capability within seconds of startup.

Privilege abuse chain (Source : GroupIB).
Privilege abuse chain (Source : GroupIB).

Command-and-control communications use WebSockets for interactive controls and streaming, with REST endpoints accepting exfiltrated data such as credentials, screenshots, SMS, and keylogs.

The current command table exposes more than fifty distinct commands, including remote UI gestures, overlay creation, APK management, camera activation, and explicit ADB setup control.

When the shell-privileged server is present, RedHook can bypass MediaProjection consent and stream screens via RTMP, increasing covert surveillance effectiveness.

This evolution underscores a key trend: attackers are increasingly weaponizing developer conveniences. The misuse of Wireless Debugging and Shizuku-style IPC demonstrates how non-exploit privilege acquisition can be achieved through automation and legitimate APIs.

Defenders should treat Accessibility and Wireless Debugging as high-value attack vectors: audit apps requesting Accessibility, block or monitor Wireless Debugging activation, restrict ADB pairing policies, and enforce least-privilege application controls.

Indicators of Compromise (IOCs)

File Indicators

  • 453333bffdd1850ea2e0647f7c805530b578919978a01b1e2be52d6eb2add946

Network IOCs

  • hxxps://api.3n7wj[.]com
  • wss://skt.3n7wj[.]com
  • wss://sktv.3n7wj[.]com

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop Accepting SLAs Written for 2019 SOCs – Here’s the 2026 AI SLA Vendor Checklist – Download Free AI SOC SLA Guide

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Related Articles

Recent News