A New Twist on Android Malware: RedHook Exploits Wireless ADB for Shell Access
Researchers at Group-IB have uncovered a fresh version of the RedHook Android malware that leverages the Android Wireless Debugging (Wireless ADB) mechanism to gain shell-level privileges without requiring a computer connection. This development marks a significant escalation in the capabilities of this mobile malware, which has been making waves since its first documentation in 2025.
RedHook’s novel approach involves tricking victims into granting it Accessibility permissions, allowing it to automatically manipulate Settings, enable Developer Options, and activate Wireless Debugging on their device. The malware then exploits the pairing code displayed on the screen to connect to the phone’s ADB service via the loopback interface (127.0.0.1). Once paired, RedHook gains shell privileges as UID 2000, which are significantly more powerful than those available to normal Android apps.
This technique is particularly concerning because it doesn’t require device rooting, making it a potential threat to all Android devices. The malware’s ability to execute shell commands, grant itself additional permissions, and modify protected Android settings without user intervention raises serious concerns about data security and user privacy. Group-IB’s analysis reveals that the current version of RedHook supports 53 server-issued commands, including screen streaming, screenshot capturing, device locking/unlocking, and app installation.
RedHook’s distribution is largely driven by social engineering tactics, with attackers posing as government agencies or financial institutions to trick victims into downloading the malware from fake Google Play sites. This highlights the importance of exercising caution when receiving unsolicited messages or calls, especially those that request sensitive information or prompt users to download software.
To protect themselves against RedHook and similar threats, Android users should adopt a cautious approach to app installations. They should only install apps from trusted sources like Google Play, scrutinize requested permissions at installation time, and ensure that Play Protect is active on their device. Moreover, users should remain vigilant when receiving messages or calls from unknown parties and avoid interacting with suspicious links or attachments.
In conclusion, the discovery of RedHook’s Wireless ADB exploitation highlights the evolving threat landscape for Android users. As security researchers continue to uncover new tactics employed by malware authors, it is essential for users to stay informed and take proactive steps to safeguard their devices. By being aware of these threats and taking necessary precautions, users can significantly reduce their risk of falling victim to malicious attacks.
Source: Bleeping Computer — 2026-07-12