본문으로 이동
Ravington
피드로 돌아가기
기술

RedHook Android malware takes over phones via wireless debugging method

Fox News
WhatsApp
RedHook Android malware takes over phones via wireless debugging method
사진: foxnews.com

핵심 요약

  • RedHook malware spreads through social engineering tactics, calling under the guise of a banker and having victims install fake applications.
  • It reaches a high privilege level on the device by abusing Android's accessibility and wireless debugging features.
  • Through the application, attackers can monitor the screen, steal passwords, secretly uninstall or install applications.
  • The malware continuously keeps itself active using methods such as playing silent audio and mutual control services.

숫자로 보기

53 different commands5-minute control alarmAndroid 11

Group-IB security researchers have investigated a new Android malware named RedHook. The attacks begin with individuals acting as bank or government officials calling the user and convincing them to install an application via a fake Google Play Store page. This installed application forces the enabling of Android's Accessibility permission, taking control of the device.

RedHook exploits the Wireless Debugging feature introduced in Android 11 to obtain shell-level privileges. Thanks to this privilege, the malware can execute system commands inaccessible to normal applications, change protected settings, monitor the screen, and record keystrokes. Even though it does not achieve full root access, it can perform serious actions such as disabling the device's security software or installing new malicious applications.

The malware uses highly advanced persistence methods to prevent it from being forcibly removed from the device. It plays silent audio in the background to ensure the operating system considers the process important, and it contains two services that monitor each other to prevent crashing. Experts warn to be cautious of signs such as receiving an urgent call or being asked for accessibility permissions, and advise against installing applications from unauthorized sources.

반응 남기기

다음 기사Hyundai's Atlas Robot Sparks Labor Union Movement in Korea

이 기사에 대해 질문

답변은 이 기사만을 바탕으로 AI가 생성합니다.

자주 묻는 질문

How does the RedHook malware infect the device?
Attackers call the user under the name of a bank official or government agency, tricking them into installing an application (APK) via a fake website.
Can this malware provide full control (root) on the device?
No, RedHook does not achieve full root access on the device; however, by using the Wireless Debugging feature, it gains system privileges far beyond those of normal applications.
Why does it become difficult to delete the application after RedHook has infected the device?
Because the malware prevents itself from being shut down by the Android system using CPU wake locks, playing silent audio, and two services that restart each other.

AI가 생성한 짧은 요약입니다. 전문은 출처에 있습니다.

출처에서 전문 읽기foxnews.com콘텐츠 제작 방식

관련 뉴스