RedHook, an Android Remote Access Trojan (RAT) first profiled in July 2025, has resurfaced with a markedly more dangerous capability: autonomous abuse of Android’s ADB Wireless Debugging to acquire shell-level privileges (uid 2000).
While its baseline toolkit screen streaming, keylogging, Accessibility-driven UI manipulation and credential theft remains intact, the latest RedHook builds demonstrate a deliberate move toward privilege escalation and resilient persistence by repurposing legitimate developer tooling and open-source frameworks.
At the heart of this escalation is RedHook’s use of Accessibility permissions to programmatically enable Developer Options and toggle Wireless Debugging.
The trojan simulates the exact UI interactions a user would perform tapping the build number multiple times, navigating Developer Options, and initiating Wireless Debugging pairing while running in the background behind a full-screen overlay.
This stepwise automation removes the need for a physical host or user awareness and positions Wireless Debugging as an on-device gateway to elevated capabilities.
RedHook embeds an ADB client and leverages the Shizuku model to run a privileged server process under shell uid 2000. Shizuku’s approach allowing an app to connect locally to the device’s ADB daemon over loopback has legitimate uses for enthusiasts and developers.
Once the shell-level server is active, the malware can grant itself runtime permissions, write into Settings.Secure (including WRITE_SECURE_SETTINGS), execute arbitrary shell commands, install or uninstall apps silently, and capture low-level touch events all without additional user prompts.
Distribution remains social-engineering driven. Operators distribute malicious APKs via spoofed government and financial sites and rely on voice or messaging-based persuasion to convince victims to install.

GroupIB Researchers said that, RedHook repurposes that pattern to spawn a privileged server (observed as libmx.so), expose Binder IPC interfaces, and execute protected system APIs.
RedHook Abuses Accessibility
Notably, payload hosting uses reputable cloud and development infrastructures Amazon S3 and GitHub among them to improve delivery reliability and avoid immediate takedown.
Recent telemetry shows an expansion of targeting from Vietnam into Indonesia, signaling a broader Southeast Asian campaign footprint.

RedHook’s persistence stack combines several advanced techniques to survive reboots and process kills.
The malware uses a one-pixel activity to maintain foreground status while the screen is off, plays silent audio in a MediaSession to elevate process priority, holds WakeLocks to prevent suspension, and adjusts its process oom_score_adj to -1000 to make itself the last candidate for termination.
A two-process mutual resurrection mechanism cross-process binding with BIND_AUTO_CREATE and periodic alarms ensures services restart if terminated.
On BOOT_COMPLETED the app re-enables Wireless ADB, reloads ADB keys, and reestablishes the privileged helper to restore full capability within seconds of startup.

Command-and-control communications use WebSockets for interactive controls and streaming, with REST endpoints accepting exfiltrated data such as credentials, screenshots, SMS, and keylogs.
The current command table exposes more than fifty distinct commands, including remote UI gestures, overlay creation, APK management, camera activation, and explicit ADB setup control.
When the shell-privileged server is present, RedHook can bypass MediaProjection consent and stream screens via RTMP, increasing covert surveillance effectiveness.
This evolution underscores a key trend: attackers are increasingly weaponizing developer conveniences. The misuse of Wireless Debugging and Shizuku-style IPC demonstrates how non-exploit privilege acquisition can be achieved through automation and legitimate APIs.
Defenders should treat Accessibility and Wireless Debugging as high-value attack vectors: audit apps requesting Accessibility, block or monitor Wireless Debugging activation, restrict ADB pairing policies, and enforce least-privilege application controls.
Indicators of Compromise (IOCs)
File Indicators
- 453333bffdd1850ea2e0647f7c805530b578919978a01b1e2be52d6eb2add946
Network IOCs
- hxxps://api.3n7wj[.]com
- wss://skt.3n7wj[.]com
- wss://sktv.3n7wj[.]com
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stop Accepting SLAs Written for 2019 SOCs – Here’s the 2026 AI SLA Vendor Checklist – Download Free AI SOC SLA Guide





