RedWing Stealer malware targets clients of 12 Uzbek banks
Read more
UzDaily
uzdaily.uz

RedWing Stealer malware targets clients of 12 Uzbek banks

Clients of twelve Uzbek banks have become targets of a new version of the RedWing Stealer malware for Android. This program allows attackers to intercept SMS messages, read notifications, and obtain other confidential information from infected devices.

The company F6 discovered over 800 samples of this malware, which were distributed between May and September 2026. RedWing Stealer is an updated version of the RedWing malware family. Unlike the previous version of the banking Trojan, which mainly focused on remote control of compromised devices, the new modification is primarily designed for data collection.

According to specialists from F6's threat analysis department, the malware was distributed disguised as various Android applications. These included 18+ content viewing services, VPN applications, as well as modifications and cheats for popular mobile games.

Specifically, RedWing Stealer disguised itself as applications related to the games Minecraft, Roblox, Standoff 2, Brawl Stars, Oxide, Exile, Skyrim, and PUBG. Under the guise of fake VPN applications, programs such as Gosu VPN, KingVPN, KrakenVPN, HideMeVPN, and FullVPN were distributed. Additionally, the malware was presented as GooglePhoto.apk and YandexPhoto.apk files.

Such applications can mimic their declared functions while performing malicious operations in the background.

F6's research showed that RedWing Stealer targets users in several countries. The list of victims includes clients of sixteen Russian, twelve Uzbek, and seven Kazakhstani banks. The malware also attacks clients of nine Russian marketplaces and eight microfinance organizations.

After installation, RedWing Stealer scans the device for SMS messages from specific senders and transmits this information to the malware operators. This poses a potential threat to users of banking services where SMS are used for transaction confirmation or receiving one-time codes.

In addition to SMS, the malware is capable of reading push notifications, as well as collecting information about the device, its location and status, connected SIM cards, call history, contacts, and installed applications. RedWing Stealer can also independently send SMS messages and USSD requests, open web links, and hide its icon on the device.

To function, the malicious application requires the user to grant it a number of permissions. Initially, the program requests full access to SMS messages, which allows it to read and send messages, including USSD commands. Then, the application requests permission to run in the background and auto-start to continue operating after the user exits the application or restarts the device.

After obtaining the necessary permissions, the program asks the user to enter a PIN code. According to the F6 study, the entered data is immediately sent to the attackers' server. After this, the application enters the background mode and continues transmitting information from the device without the user's knowledge.

Popular